| Release Date | Dec 28, 2005 |
| Severity | High |
| Impact | System compromise, arbitrary code execution. |
| Description | This indicates an attempt to exploit a vulnerability in the Microsoft Windows WMF graphics rendering engine. A remote attacker can use the SetProcAbort function in a WMF image file to include code that will execute when the image is viewed. The attacker may be able to execute arbitrary code on the system, with administrator privileges if the image is viewed by an administrator. |
| Affected Products | Microsoft Windows 2000 SP4 Microsoft Windows XP SP1 and SP2 Microsoft Windows XP Professional x64 Edition Microsoft Windows Server 2003 and SP1 Microsoft Windows Server 2003 for Itanium-based Systems and SP1 Microsoft Windows Server 2003 x64 Edition Microsoft Windows 98, Microsoft Windows 98 Second Edition (SE) Microsoft Windows Millennium Edition (ME) |
| Recommended Actions | Microsoft Security Bulletin MS06-001 addresses this issue. http://www.microsoft.com/technet/security/Bulletin/MS06-001.mspx |
| Common Vulnerabilities and Exposures (CVE) | http://cve.mitre.org/cgi-bin/cvename.cgi?name=2005-4560
|
| Microsoft Bulletin ID | MS06-001 http://www.microsoft.com/technet/security/Bulletin/MS06-001.mspx |
| Reference/s | http://www.securityfocus.com/bid/16074 (BugTraq) http://www.vupen.com/english/advisories/2005/3086 (FrSIRT)
|