First published: Tue Jan 10 2006(Updated: )
An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 98 | ||
Microsoft Windows XP | =sp1 | |
Microsoft Windows Server 2003 | =sp1 | |
Microsoft Windows Server 2003 | =r2 | |
Microsoft Windows | ||
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows 9x | =gold |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0020 is considered a high severity vulnerability due to its potential to cause denial of service and execute arbitrary code.
To fix CVE-2006-0020, apply the latest security patches provided by Microsoft for the affected operating systems.
CVE-2006-0020 affects Microsoft WMF parsing applications used in Internet Explorer on Windows 98SE, Windows 2000 SP4, Windows XP, and Windows 2003 Server.
CVE-2006-0020 can be exploited through a specially crafted WMF file that leads to a system crash or arbitrary code execution.
CVE-2006-0020 primarily affects outdated versions of Windows, making it less relevant for modern systems with current security updates.