Microsoft Windows Graphics Rendering Engine WMF SetAbortProc Code Execution Vulnerability
BID:16074
Info
Microsoft Windows Graphics Rendering Engine WMF SetAbortProc Code Execution Vulnerability
| Bugtraq ID: | 16074 |
| Class: | Design Error |
| CVE: |
CVE-2005-4560 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Dec 28 2005 12:00AM |
| Updated: | Nov 02 2007 06:36PM |
| Credit: | The individual responsible for discovering this issue not currently known. |
| Vulnerable: |
XnView XnView Standard 1.80.3 XnView XnView Minimal 1.80.3 XnView XnView Complete 1.80.3 Wine Windows API Emulator 0.9.4 Wine Windows API Emulator 0.9.3 Wine Windows API Emulator 0.9.2 Wine Windows API Emulator 0.9.1 Wine Windows API Emulator 0.9 Nortel Networks Symposium TAPI Service Provider Nortel Networks Symposium Agent Nortel Networks Passport Multiservice Data Manager (MDM) Nortel Networks Optivity Telephony Manager (OTM) Nortel Networks Multimedia Communication Platform Nortel Networks MCS 5200 3.0 Nortel Networks MCS 5100 3.0 Nortel Networks IP Address Domain Manager Nortel Networks Enterprise Network Management System Nortel Networks Contact Center Web Client Nortel Networks Contact Center Multimedia Nortel Networks Contact Center Manager Nortel Networks Contact Center Express Nortel Networks Contact Center Nortel Networks Communication Control Toolkit 0 Nortel Networks Centrex IP Client Manager Nortel Networks CallPilot 4.0 Nortel Networks CallPilot 3.0 Nortel Networks CallPilot 2.0 Nortel Networks CallPilot 1.0.7 Microsoft Windows XP Tablet PC Edition SP2 Microsoft Windows XP Tablet PC Edition SP1 Microsoft Windows XP Tablet PC Edition Microsoft Windows XP Professional x64 Edition Microsoft Windows XP Professional SP2 Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Media Center Edition SP2 Microsoft Windows XP Media Center Edition SP1 Microsoft Windows XP Media Center Edition Microsoft Windows XP Home SP2 Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows Vista December CTP Microsoft Windows Vista Beta 1 Microsoft Windows Vista Beta Microsoft Windows Server 2003 Web Edition SP1 Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2003 Standard x64 Edition Microsoft Windows Server 2003 Standard Edition SP1 Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Enterprise x64 Edition Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Microsoft Windows Server 2003 Enterprise Edition Itanium 0 Microsoft Windows Server 2003 Enterprise Edition SP1 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter x64 Edition Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Microsoft Windows Server 2003 Datacenter Edition Itanium 0 Microsoft Windows Server 2003 Datacenter Edition SP1 Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows NT Workstation 4.0 SP6a Microsoft Windows NT Workstation 4.0 SP6 Microsoft Windows NT Workstation 4.0 SP5 Microsoft Windows NT Workstation 4.0 SP4 Microsoft Windows NT Workstation 4.0 SP3 Microsoft Windows NT Workstation 4.0 SP2 Microsoft Windows NT Workstation 4.0 SP1 Microsoft Windows NT Workstation 4.0 Microsoft Windows NT Terminal Server 4.0 SP6a Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows ME Microsoft Windows 98SE Microsoft Windows 98 Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server IrfanView IrfanView 3.98 IrfanView IrfanView 3.97 IrfanView IrfanView 3.95 IBM Lotus Notes 6.5.4 IBM Lotus Notes 6.5.3 IBM Lotus Notes 6.5.2 IBM Lotus Notes 6.5.1 IBM Lotus Notes 6.5 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Avaya Unified Communications Center S3400 Avaya S8100 Media Servers R9 Avaya S8100 Media Servers R8 Avaya S8100 Media Servers R7 Avaya S8100 Media Servers R6 Avaya S8100 Media Servers R12 Avaya S8100 Media Servers R11 Avaya S8100 Media Servers R10 Avaya S8100 Media Servers 0 Avaya Modular Messaging (MAS) Avaya IP600 Media Servers R9 Avaya IP600 Media Servers R8 Avaya IP600 Media Servers R7 Avaya IP600 Media Servers R6 Avaya IP600 Media Servers R12 Avaya IP600 Media Servers R11 Avaya IP600 Media Servers R10 Avaya IP600 Media Servers Avaya DefinityOne Media Servers R9 Avaya DefinityOne Media Servers R8 Avaya DefinityOne Media Servers R7 Avaya DefinityOne Media Servers R6 Avaya DefinityOne Media Servers R12 Avaya DefinityOne Media Servers R11 Avaya DefinityOne Media Servers R10 Avaya DefinityOne Media Servers |
| Not Vulnerable: | |
Discussion
Microsoft Windows Graphics Rendering Engine WMF SetAbortProc Code Execution Vulnerability
Microsoft Windows WMF graphics rendering engine is affected by a remote code-execution vulnerability. This issue affects the 'SetAbortProc' function.
The problem presents itself when a user views a malicious WMF formatted file, triggering the vulnerability when the engine attempts to parse the file.
The issue may be exploited remotely or locally. Any remote code execution that occurs will be with the privileges of the user viewing a malicious image. An attacker may gain SYSTEM privileges if an administrator views the malicious file.
Local code execution may facilitate a complete compromise.
Microsoft Windows WMF graphics rendering engine is affected by a remote code-execution vulnerability. This issue affects the 'SetAbortProc' function.
The problem presents itself when a user views a malicious WMF formatted file, triggering the vulnerability when the engine attempts to parse the file.
The issue may be exploited remotely or locally. Any remote code execution that occurs will be with the privileges of the user viewing a malicious image. An attacker may gain SYSTEM privileges if an administrator views the malicious file.
Local code execution may facilitate a complete compromise.
Exploit / POC
Microsoft Windows Graphics Rendering Engine WMF SetAbortProc Code Execution Vulnerability
A remote code-execution exploit that triggers this issue is currently circulating in the wild.
An exploit (ie_xp_pfv_metafile.pm revision 1.6) has been released for the Metasploit Framework.
A new exploit (ie_xp_pfv_metafile-19.pm revision 1.9) has been released for the Metasploit Framework. Reports indicate that this exploit can bypass current antivirus and snort signatures.
UPDATE: There are a reports of a worm that is exploiting this vulnerability over MSN. The worm is allegedly enticing users to download a file entitled "xmas-2006 FUNNY.jpg" through links distributed in instant messages. Symantec is currently investigating this. This BID will be updated as more information emerges.
Exploit code wmf_exp.c has been supplied by Unl0ck Research Team. Symantec has not verified the integrity of this exploit.
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
A remote code-execution exploit that triggers this issue is currently circulating in the wild.
An exploit (ie_xp_pfv_metafile.pm revision 1.6) has been released for the Metasploit Framework.
A new exploit (ie_xp_pfv_metafile-19.pm revision 1.9) has been released for the Metasploit Framework. Reports indicate that this exploit can bypass current antivirus and snort signatures.
UPDATE: There are a reports of a worm that is exploiting this vulnerability over MSN. The worm is allegedly enticing users to download a file entitled "xmas-2006 FUNNY.jpg" through links distributed in instant messages. Symantec is currently investigating this. This BID will be updated as more information emerges.
Exploit code wmf_exp.c has been supplied by Unl0ck Research Team. Symantec has not verified the integrity of this exploit.
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft Windows Graphics Rendering Engine WMF SetAbortProc Code Execution Vulnerability
Solution:
Please see the referenced advisories for more information:
- Microsoft has released a security advisory (Microsoft Security Advisory (912840)) confirming this issue. The referenced advisory contains information about workarounds; the vendor plans to release updates in the near future.
- Microsoft has released a security advisory (Microsoft Security Bulletin MS06-001) to address this issue for supported operating systems. Reports indicate that users who have disabled Microsoft Windows Picture and Fax Viewer by deregistering 'shimgvw.dll' may have to register it manually after applying fixes released by Microsoft. Please see the Workaround section for instructions on registering 'shimgvw.dll'.
- Avaya has released advisory ASA-2006-001 to identify vulnerable Avaya products. Avaya recommends installing Microsoft fixes to address this issue on affected computers.
- Gentoo Linux has released advisory GLSA 200601-09 to address this issue in Wine. Users of affected packages should execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=app-emulation/wine-20050930"
- Nortel Networks has released a security advisory to address this issue in various products.
- Microsoft has released patches to address this issue in Microsoft Windows Vista Beta 1 and Windows Vista December CTP (Community Technology Preview). See fixes for the Windows Vista December CTP (Community Technology Preview) patch. Users are advised to contact Microsoft for the Windows Vista Beta 1 patch.
- Gentoo has released advisory GLSA 200601-09:02 to replace fixes that were released as part of the Gentoo advisory 200601-09. The fixes released in the previous advisory did not properly address this issue. Please see the referenced advisory for more information. All Wine users should re-emerge Wine by carrying out the following commands:
emerge --sync
emerge --ask --oneshot --verbose ">=app-emulation/wine-0.9.0"
- Debian has released advisory DSA 954-1 to address this issue in Wine. Please see the referenced advisory for more information.
Microsoft Windows Server 2003 Datacenter Edition SP1
Microsoft Windows XP Media Center Edition SP1
Microsoft Windows XP Tablet PC Edition SP2
Microsoft Windows Server 2003 Standard Edition SP1
Microsoft Windows Server 2003 Standard Edition
Microsoft Windows Server 2003 Enterprise x64 Edition
Microsoft Windows Server 2003 Datacenter Edition Itanium 0
Microsoft Windows Server 2003 Enterprise Edition SP1
Microsoft Windows Vista December CTP
Microsoft Windows Server 2003 Datacenter Edition
Microsoft Windows 2000 Advanced Server SP4
Microsoft Windows XP Home SP1
Microsoft Windows XP Professional x64 Edition
Microsoft Windows Server 2003 Datacenter Edition Itanium SP1
Microsoft Windows Server 2003 Standard x64 Edition
Solution:
Please see the referenced advisories for more information:
- Microsoft has released a security advisory (Microsoft Security Advisory (912840)) confirming this issue. The referenced advisory contains information about workarounds; the vendor plans to release updates in the near future.
- Microsoft has released a security advisory (Microsoft Security Bulletin MS06-001) to address this issue for supported operating systems. Reports indicate that users who have disabled Microsoft Windows Picture and Fax Viewer by deregistering 'shimgvw.dll' may have to register it manually after applying fixes released by Microsoft. Please see the Workaround section for instructions on registering 'shimgvw.dll'.
- Avaya has released advisory ASA-2006-001 to identify vulnerable Avaya products. Avaya recommends installing Microsoft fixes to address this issue on affected computers.
- Gentoo Linux has released advisory GLSA 200601-09 to address this issue in Wine. Users of affected packages should execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=app-emulation/wine-20050930"
- Nortel Networks has released a security advisory to address this issue in various products.
- Microsoft has released patches to address this issue in Microsoft Windows Vista Beta 1 and Windows Vista December CTP (Community Technology Preview). See fixes for the Windows Vista December CTP (Community Technology Preview) patch. Users are advised to contact Microsoft for the Windows Vista Beta 1 patch.
- Gentoo has released advisory GLSA 200601-09:02 to replace fixes that were released as part of the Gentoo advisory 200601-09. The fixes released in the previous advisory did not properly address this issue. Please see the referenced advisory for more information. All Wine users should re-emerge Wine by carrying out the following commands:
emerge --sync
emerge --ask --oneshot --verbose ">=app-emulation/wine-0.9.0"
- Debian has released advisory DSA 954-1 to address this issue in Wine. Please see the referenced advisory for more information.
Microsoft Windows Server 2003 Datacenter Edition SP1
-
Microsoft Security Update for Windows Server 2003 (KB912919)
http://www.microsoft.com/downloads/details.aspx?familyid=1584AAE0-51CE -47D6-9A03-DB5B9077F1F2&displaylang=en
Microsoft Windows XP Media Center Edition SP1
-
Microsoft Security Update for Windows XP (KB912919)
http://www.microsoft.com/downloads/details.aspx?familyid=0C1B4C96-57AE -499E-B89B-215B7BB4D8E9&displaylang=en
Microsoft Windows XP Tablet PC Edition SP2
-
Microsoft Security Update for Windows XP (KB912919)
http://www.microsoft.com/downloads/details.aspx?familyid=0C1B4C96-57AE -499E-B89B-215B7BB4D8E9&displaylang=en
Microsoft Windows Server 2003 Standard Edition SP1
-
Microsoft Security Update for Windows Server 2003 (KB912919)
http://www.microsoft.com/downloads/details.aspx?familyid=1584AAE0-51CE -47D6-9A03-DB5B9077F1F2&displaylang=en
Microsoft Windows Server 2003 Standard Edition
-
Microsoft Security Update for Windows Server 2003 (KB912919)
http://www.microsoft.com/downloads/details.aspx?familyid=1584AAE0-51CE -47D6-9A03-DB5B9077F1F2&displaylang=en
Microsoft Windows Server 2003 Enterprise x64 Edition
-
Microsoft Security Update for Windows Server x64 Edition (KB912919)
http://www.microsoft.com/downloads/details.aspx?familyid=A8F4DCBA-5D28 -4D9D-A6A4-3B71108CFE2D&displaylang=en
Microsoft Windows Server 2003 Datacenter Edition Itanium 0
-
Microsoft Security Update for Windows Server 2003 64-bit Itanium Edition (KB912919)
http://www.microsoft.com/downloads/details.aspx?familyid=6E372D41-2C16 -415E-8306-A5CA8845CC09&displaylang=en
Microsoft Windows Server 2003 Enterprise Edition SP1
-
Microsoft Security Update for Windows Server 2003 (KB912919)
http://www.microsoft.com/downloads/details.aspx?familyid=1584AAE0-51CE -47D6-9A03-DB5B9077F1F2&displaylang=en
Microsoft Windows Vista December CTP
-
Microsoft Security Update for Windows Vista December CTP (KB912919)
http://www.microsoft.com/downloads/details.aspx?familyid=228f2cdc-7148 -4002-86bb-e4ade080ea86&displaylang=en
Microsoft Windows Server 2003 Datacenter Edition
-
Microsoft Security Update for Windows Server 2003 (KB912919)
http://www.microsoft.com/downloads/details.aspx?familyid=1584AAE0-51CE -47D6-9A03-DB5B9077F1F2&displaylang=en
Microsoft Windows 2000 Advanced Server SP4
-
Microsoft Security Update for Windows 2000 (KB912919)
http://www.microsoft.com/downloads/details.aspx?familyid=AA9E27BD-CB9A -4EF1-92A3-00FFE7B2AC74&displaylang=en
Microsoft Windows XP Home SP1
-
Microsoft Security Update for Windows XP (KB912919)
http://www.microsoft.com/downloads/details.aspx?familyid=0C1B4C96-57AE -499E-B89B-215B7BB4D8E9&displaylang=en
Microsoft Windows XP Professional x64 Edition
-
Microsoft Security Update for Windows XP x64 Edition (KB912919)
http://www.microsoft.com/downloads/details.aspx?familyid=3A1166E6-5E9E -4E73-BCD4-28ECA6ECE877&displaylang=en
Microsoft Windows Server 2003 Datacenter Edition Itanium SP1
-
Microsoft Security Update for Windows Server 2003 64-bit Itanium Edition (KB912919)
http://www.microsoft.com/downloads/details.aspx?familyid=6E372D41-2C16 -415E-8306-A5CA8845CC09&displaylang=en
Microsoft Windows Server 2003 Standard x64 Edition
-
Microsoft Security Update for Windows Server x64 Edition (KB912919)
http://www.microsoft.com/downloads/details.aspx?familyid=A8F4DCBA-5D28 -4D9D-A6A4-3B71108CFE2D&displaylang=en
References
Microsoft Windows Graphics Rendering Engine WMF SetAbortProc Code Execution Vulnerability
References:
References:
- [ BULLETIN ] NORTEL RESPONSE TO MICROSOFT SECURITY BULLETIN MS06-001 (Nortel Networks)
- [[test title]] ([[test author]])
- ASA-2006-001 - WMF vulnerability in Windows (MS06-001) (Avaya)
- DSA-954-1 wine -- design flaw (Debian)
- Lotus Notes vulnerable to MS Windows graphics rendering engine bug (NIST.org)
- Microsoft Security Advisory (912840) (Microsoft)
- Microsoft Security Bulletin MS06-001 (Microsoft)
- Microsoft Ships First Vista Security Patches (Eweek)
- Vulnerabilities in Graphics Rendering Engine May Still Exist Even After Applying (Josh)
- Vulnerability Note VU#181038 - Microsoft Windows Metafile handler buffer overflo (CERT)
- WMF Exploit ([email protected])