Back

CVE-2005-4560

The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.

Published: Dec 28, 2005 Modified: Jun 16, 2026
CWE-20

CVSS Metrics

Affected Products (16)

Vendor Product Version
microsoft windows_2003_server enterprise
microsoft windows_2003_server enterprise
microsoft windows_2003_server r2
microsoft windows_2003_server r2
microsoft windows_2003_server standard
microsoft windows_2003_server standard
microsoft windows_2003_server web
microsoft windows_2003_server web
microsoft windows_xp *
microsoft windows_xp *
microsoft windows_xp *
microsoft windows_xp *
microsoft windows_xp *
microsoft windows_xp *
microsoft windows_xp *
microsoft windows_xp *

GitHub Security Advisory GHSA-w94w-cg39-6r6h

The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 86.09%

Top 0% most likely to be exploited

Threat Score 65.8 / 100

Data Sources

NVD EPSS GitHub