CVE-2005-4560
EXPLOITED IN THE WILDMicrosoft Windows - RCE
Title source: llmDescription
The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16612
metasploit
WORKING POC
GREAT
by hdm · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/ms06_001_wmf_setabortproc.rb
References (37)
... and 17 more
Scores
EPSS
0.9027
EPSS Percentile
99.6%
Details
VulnCheck KEV
2005-12-28
InTheWild.io
2018-10-19
CWE
CWE-20
Status
published
Products (5)
microsoft/windows_2003_server
enterprise (2 CPE variants)
microsoft/windows_2003_server
r2 (2 CPE variants)
microsoft/windows_2003_server
standard (2 CPE variants)
microsoft/windows_2003_server
web (2 CPE variants)
microsoft/windows_xp
(8 CPE variants)
Published
Dec 28, 2005
Tracked Since
Feb 18, 2026