Back

CVE-2005-2124

Unspecified vulnerability in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1, related to "An unchecked buffer" and possibly buffer overflows, allows remote attackers to execute arbitrary code via a crafted Windows Metafile (WMF) format image, aka "Windows Metafile Vulnerability."

Published: Nov 29, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (9)

Vendor Product Version
microsoft windows_2000 *
microsoft windows_2003_server 64-bit
microsoft windows_2003_server itanium
microsoft windows_2003_server r2
microsoft windows_2003_server sp1
microsoft windows_2003_server sp1
microsoft windows_xp *
microsoft windows_xp *
microsoft windows_xp *

GitHub Security Advisory GHSA-w8ch-g4f3-mw6x

Unspecified vulnerability in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP...

Risk Scores

CVSS Score 7.6 / 10
EPSS Score 55.71%

Top 1% most likely to be exploited

Threat Score 47.1 / 100

Data Sources

NVD EPSS GitHub