Back
CVE-2005-4560
The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.
Published: Dec 28, 2005
Modified: Jun 16, 2026
CWE-20
CVSS Metrics
Affected Products (16)
| Vendor | Product | Version |
|---|---|---|
| microsoft | windows_2003_server | enterprise |
| microsoft | windows_2003_server | enterprise |
| microsoft | windows_2003_server | r2 |
| microsoft | windows_2003_server | r2 |
| microsoft | windows_2003_server | standard |
| microsoft | windows_2003_server | standard |
| microsoft | windows_2003_server | web |
| microsoft | windows_2003_server | web |
| microsoft | windows_xp | * |
| microsoft | windows_xp | * |
| microsoft | windows_xp | * |
| microsoft | windows_xp | * |
| microsoft | windows_xp | * |
| microsoft | windows_xp | * |
| microsoft | windows_xp | * |
| microsoft | windows_xp | * |
GitHub Security Advisory GHSA-w94w-cg39-6r6h
The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote...
References (74)
- http://linuxbox.org/pipermail/funsec/2006-January/002455.html
- http://secunia.com/advisories/18255 Vendor Advisory
- http://secunia.com/advisories/18311 Vendor Advisory
- http://secunia.com/advisories/18364 Vendor Advisory
- http://secunia.com/advisories/18415 Vendor Advisory
- http://securitytracker.com/id?1015416 Exploit
- http://support.avaya.com/elmodocs2/security/ASA-2006-001.htm Vendor Advisory
- http://vil.mcafeesecurity.com/vil/content/v_137760.htm Vendor Advisory
- http://www.f-secure.com/weblog/archives/archive-122005.html#00000753 Exploit, Vendor Advisory
- http://www.kb.cert.org/vuls/id/181038 Third Party Advisory, US Government Resource
- http://www.microsoft.com/technet/security/advisory/912840.mspx Vendor Advisory
- http://www.securityfocus.com/archive/1/420288/100/0/threaded
- http://www.securityfocus.com/archive/1/420351/100/0/threaded
- http://www.securityfocus.com/archive/1/420357/100/0/threaded
- http://www.securityfocus.com/archive/1/420367/100/0/threaded
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
86.09%
Top 0% most likely to be exploited
Threat Score
65.8 / 100
Data Sources
NVD
EPSS
GitHub