CVE-2005-4560

EXPLOITED IN THE WILD

Microsoft Windows - RCE

Title source: llm

Description

The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16612
metasploit WORKING POC GREAT
by hdm · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/ms06_001_wmf_setabortproc.rb

References (37)

... and 17 more

Scores

EPSS 0.9027
EPSS Percentile 99.6%

Details

VulnCheck KEV 2005-12-28
InTheWild.io 2018-10-19
CWE
CWE-20
Status published
Products (5)
microsoft/windows_2003_server enterprise (2 CPE variants)
microsoft/windows_2003_server r2 (2 CPE variants)
microsoft/windows_2003_server standard (2 CPE variants)
microsoft/windows_2003_server web (2 CPE variants)
microsoft/windows_xp (8 CPE variants)
Published Dec 28, 2005
Tracked Since Feb 18, 2026