CVE-2005-4560: Input Validation
The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4560?
CVE-2005-4560 is considered critical due to its potential to allow remote code execution.
How do I fix CVE-2005-4560?
To fix CVE-2005-4560, update your Microsoft Windows software to the latest security patches provided by Microsoft.
What systems are affected by CVE-2005-4560?
CVE-2005-4560 affects various versions of Microsoft Windows XP and Windows 2003 Server.
What type of vulnerability is CVE-2005-4560?
CVE-2005-4560 is a remote code execution vulnerability within the Windows Graphical Device Interface.
Can CVE-2005-4560 be exploited by an attacker?
Yes, an attacker can exploit CVE-2005-4560 by tricking a user into opening a malicious Windows Metafile image.