Microsoft Windows WMF "SETABORTPROC" Arbitrary Code Execution

  Severity: HIGH
  CVE Identifier: CVE-2005-4560,MS06-001
  Advisory Date: JUL 21, 2015

  DESCRIPTION

The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.

  TREND MICRO PROTECTION INFORMATION

Apply associated Trend Micro DPI Rules.

  SOLUTION

  Trend Micro Deep Security DPI Rule Number: 1000162
  Trend Micro Deep Security DPI Rule Name: 1000162 - Microsoft Windows WMF "SETABORTPROC" Arbitrary Code Execution

  AFFECTED SOFTWARE AND VERSION

  • Microsoft Windows Server 2003 Datacenter
  • Microsoft Windows Server 2003 Datacenter SP1
  • Microsoft Windows Server 2003 Enterprise
  • Microsoft Windows Server 2003 Enterprise SP1
  • Microsoft Windows Server 2003 Standard
  • Microsoft Windows Server 2003 Standard SP1
  • Microsoft Windows Server 2003 Web
  • Microsoft Windows Server 2003 Web SP1
  • Microsoft Windows XP Home
  • Microsoft Windows XP Home SP1
  • Microsoft Windows XP Home SP2
  • Microsoft Windows XP Media Center
  • Microsoft Windows XP Media Center SP1
  • Microsoft Windows XP Media Center SP2
  • Microsoft Windows XP Professional
  • Microsoft Windows XP Professional SP1
  • Microsoft Windows XP Professional SP2
  • Microsoft Windows XP Tablet PC
  • Microsoft Windows XP Tablet PC SP1
  • Microsoft Windows XP Tablet PC SP2