CVE-2005-2124
Summary
| CVE | CVE-2005-2124 |
|---|---|
| State | PUBLISHED |
| Assigner | microsoft |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-11-29 21:03:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Unspecified vulnerability in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1, related to "An unchecked buffer" and possibly buffer overflows, allows remote attackers to execute arbitrary code via a crafted Windows Metafile (WMF) format image, aka "Windows Metafile Vulnerability." |
Risk And Classification
Primary CVSS: v2.0 7.6 from [email protected]
AV:N/AC:H/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:H/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Microsoft | Windows 2000 | All | sp4 | All | fr |
| Operating System | Microsoft | Windows 2003 Server | 64-bit | All | All | All |
| Operating System | Microsoft | Windows 2003 Server | itanium | All | All | All |
| Operating System | Microsoft | Windows 2003 Server | r2 | All | All | All |
| Operating System | Microsoft | Windows 2003 Server | sp1 | All | All | All |
| Operating System | Microsoft | Windows 2003 Server | sp1 | All | itanium | All |
| Operating System | Microsoft | Windows Xp | All | All | 64-bit | All |
| Operating System | Microsoft | Windows Xp | All | sp1 | tablet_pc | All |
| Operating System | Microsoft | Windows Xp | All | sp2 | tablet_pc | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft Security Bulletin MS05-053 - Critical | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | |
| Windows Metafile Multiple Heap Overflows - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| US-CERT Vulnerability Note VU#433341 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Patch, Third Party Advisory, US Government Resource |
| SecurityTracker.com Archives - Microsoft Windows Buffer Overflows in Graphics Rendering Engine Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Microsoft Windows Graphics Rendering Engine WMF Format Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| US-CERT Technical Cyber Security Alert TA05-312A -- Microsoft Windows Image Processing Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| Network Security, Vulnerability Assessment, Intrusion Prevention | af854a3a-2127-422b-91ae-364da2661108 | www.eeye.com | Patch, Vendor Advisory |
| Network Security, Vulnerability Assessment, Intrusion Prevention | af854a3a-2127-422b-91ae-364da2661108 | www.eeye.com | |
| Secunia - Advisories - Microsoft Windows WMF/EMF File Rendering Arbitrary Code Execution | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Secunia - Advisories - Nortel Centrex IP Client Manager Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| support.avaya.com/elmodocs2/security/ASA-2005-228.pdf | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| Secunia - Advisories - Avaya Products Microsoft Windows WMF/EMF Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.