First published: Wed Apr 04 2007(Updated: )
The Graphics Rendering Engine in Microsoft Windows 2000 SP4 and XP SP2 allows local users to gain privileges via "invalid application window sizes" in layered application windows, aka the "GDI Invalid Window Size Elevation of Privilege Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows XP | =sp2 | |
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =gold |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5586 has a severity rating classified as 'high' due to its potential to allow local users to gain elevated privileges.
To fix CVE-2006-5586, update Microsoft Windows 2000 to Service Pack 4 and Microsoft Windows XP to Service Pack 3 or higher.
CVE-2006-5586 affects Microsoft Windows 2000 SP4 and Microsoft Windows XP SP2 and SP2 Professional x64.
CVE-2006-5586 is classified as an elevation of privilege vulnerability associated with the Graphics Rendering Engine.
CVE-2006-5586 cannot be exploited remotely as it requires local access to the affected systems.