Vulnerabilities > CVE-2005-2124 - Unspecified vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Unspecified vulnerability in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1, related to "An unchecked buffer" and possibly buffer overflows, allows remote attackers to execute arbitrary code via a crafted Windows Metafile (WMF) format image, aka "Windows Metafile Vulnerability."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 9 |
Exploit-Db
description MS Windows Metafile (mtNoObjects) Denial of Service Exploit (MS05-053). CVE-2005-0803,CVE-2005-2123,CVE-2005-2124. Dos exploit for windows platform id EDB-ID:1346 last seen 2016-01-31 modified 2005-11-30 published 2005-11-30 reporter Winny Thomas source https://www.exploit-db.com/download/1346/ title Microsoft Windows Metafile - mtNoObjects Denial of Service Exploit MS05-053 description MS Windows Metafile (gdi32.dll) Denial of Service Exploit (MS05-053). CVE-2005-2124. Dos exploit for windows platform id EDB-ID:1343 last seen 2016-01-31 modified 2005-11-29 published 2005-11-29 reporter Winny Thomas source https://www.exploit-db.com/download/1343/ title Microsoft Windows Metafile gdi32.dll Denial of Service Exploit MS05-053
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS05-053.NASL |
description | The remote host contains a version of Microsoft Windows missing a critical security update to fix several vulnerabilities in the Graphic Rendering Engine, and in the way Windows handles Metafiles. An attacker could exploit these flaws to execute arbitrary code on the remote host by sending a specially crafted Windows Metafile (WMF) or Enhanced Metafile (EMF) to a victim on the remote host. When viewing the malformed file, a buffer overflow condition occurs that may allow the execution of arbitrary code with the privileges of the user. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 20172 |
published | 2005-11-08 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/20172 |
title | MS05-053: Vulnerabilities in Graphics Rendering Engine Could Allow Code Execution (896424) |
code |
|
References
- http://secunia.com/advisories/17223
- http://secunia.com/advisories/17461
- http://secunia.com/advisories/17498
- http://securityreason.com/securityalert/161
- http://securitytracker.com/id?1015168
- http://support.avaya.com/elmodocs2/security/ASA-2005-228.pdf
- http://www.eeye.com/html/research/advisories/AD20051108a.html
- http://www.eeye.com/html/research/advisories/AD20051108b.html
- http://www.kb.cert.org/vuls/id/433341
- http://www.securityfocus.com/bid/15356
- http://www.us-cert.gov/cas/techalerts/TA05-312A.html
- http://www.vupen.com/english/advisories/2005/2348
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-053