Vulnerabilities > CVE-2006-4071 - Remote Denial of Service vulnerability in Microsoft Windows 2003 Server and Windows XP

047910
CVSS 2.6 - LOW
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
high complexity
microsoft
exploit available

Summary

Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP, Server 2003, and possibly other versions, allows user-assisted attackers to cause a denial of service (application crash) via a crafted WMF file.

Exploit-Db

descriptionMS Windows Explorer (WMF) CreateBrushIndirect DoS Exploit. CVE-2006-4071. Dos exploit for windows platform
fileexploits/windows/dos/3111.pl
idEDB-ID:3111
last seen2016-01-31
modified2007-01-13
platformwindows
port
published2007-01-13
reportercyanid-E
sourcehttps://www.exploit-db.com/download/3111/
titleMicrosoft Windows - Explorer WMF CreateBrushIndirect DoS Exploit
typedos