Back
CVE-2005-2124
Unspecified vulnerability in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1, related to "An unchecked buffer" and possibly buffer overflows, allows remote attackers to execute arbitrary code via a crafted Windows Metafile (WMF) format image, aka "Windows Metafile Vulnerability."
Published: Nov 29, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (9)
| Vendor | Product | Version |
|---|---|---|
| microsoft | windows_2000 | * |
| microsoft | windows_2003_server | 64-bit |
| microsoft | windows_2003_server | itanium |
| microsoft | windows_2003_server | r2 |
| microsoft | windows_2003_server | sp1 |
| microsoft | windows_2003_server | sp1 |
| microsoft | windows_xp | * |
| microsoft | windows_xp | * |
| microsoft | windows_xp | * |
GitHub Security Advisory GHSA-w8ch-g4f3-mw6x
Unspecified vulnerability in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP...
References (26)
- http://secunia.com/advisories/17223
- http://secunia.com/advisories/17461
- http://secunia.com/advisories/17498
- http://securityreason.com/securityalert/161
- http://securitytracker.com/id?1015168
- http://support.avaya.com/elmodocs2/security/ASA-2005-228.pdf
- http://www.eeye.com/html/research/advisories/AD20051108a.html
- http://www.eeye.com/html/research/advisories/AD20051108b.html Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/433341 Patch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/15356
- http://www.us-cert.gov/cas/techalerts/TA05-312A.html US Government Resource
- http://www.vupen.com/english/advisories/2005/2348
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-053
- http://secunia.com/advisories/17223
- http://secunia.com/advisories/17461
Risk Scores
CVSS Score
7.6 / 10
EPSS Score
55.71%
Top 1% most likely to be exploited
Threat Score
47.1 / 100
Data Sources
NVD
EPSS
GitHub