This application requires Javascript for optimal performance.

MS.IE.WMF.SetAbortProc.Code.Execution

Alias(es)

IE.XP.WMF.Code.Execution.B

Release Date

Sep 11, 2006

Severity

high

Impact

System compromise: remote code execution.

Description

This indicates a possible exploit of a vulnerability in Microsoft Windows which may allow remote attackers to execute arbitrary commands.

This vulnerability is due to an error in the rendering of Windows Metafile (WMF) image formats. It can be exploited to remotely take complete control of an affected system by convincing a user to open a malicious WMF file using a vulnerable application.

Affected Products

Microsoft Windows XP Service Pack 2 and earlier versions.
Microsoft Windows Server 2003 Service Pack 1 and earlier versions.

Recommended Actions

Apply the appropriate patch from the vendor.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2005-4560

Reference/s

http://www.securityfocus.com/bid/16074 (BugTraq)
http://www.frsirt.com/english/advisories/2005/3086 (FrSIRT)

Reference: VID-12965