Microsoft Windows WMF "SETABORTPROC" Arbitrary Code Execution
Publish Date: 21 juillet 2015
Gravité: : Élevé
Identifiant(s) CVE: : CVE-2005-4560,MS06-001
Date du conseil: 21 juillet 2015
Description
The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.
Information Exposure Rating:
Apply associated Trend Micro DPI Rules.
Solutions
Trend Micro Deep Security DPI Rule Number: 1000162
Trend Micro Deep Security DPI Rule Name: 1000162 - Microsoft Windows WMF "SETABORTPROC" Arbitrary Code Execution
Affected software and version:
- Microsoft Windows Server 2003 Datacenter
- Microsoft Windows Server 2003 Datacenter SP1
- Microsoft Windows Server 2003 Enterprise
- Microsoft Windows Server 2003 Enterprise SP1
- Microsoft Windows Server 2003 Standard
- Microsoft Windows Server 2003 Standard SP1
- Microsoft Windows Server 2003 Web
- Microsoft Windows Server 2003 Web SP1
- Microsoft Windows XP Home
- Microsoft Windows XP Home SP1
- Microsoft Windows XP Home SP2
- Microsoft Windows XP Media Center
- Microsoft Windows XP Media Center SP1
- Microsoft Windows XP Media Center SP2
- Microsoft Windows XP Professional
- Microsoft Windows XP Professional SP1
- Microsoft Windows XP Professional SP2
- Microsoft Windows XP Tablet PC
- Microsoft Windows XP Tablet PC SP1
- Microsoft Windows XP Tablet PC SP2