OSVDB ID: 21987

Title: Microsoft Windows Shimgvw.dll SETABORTPROC Function Crafted WMF Arbitrary Code Execution

Info

Disclosure

Dec 27, 2005

Discovery

Unknown

Dates

Exploit

Dec 27, 2005

Solution

Jan 05, 2006

Description

A code execution flaw exists in Windows. Shimgvw.dll fails to validate WMF files resulting in code execution via the SETABORTPROC function. With a specially crafted file, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Local / Remote
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Patch / RCS
Exploit: Exploit Public, Exploit Commercial
Disclosure: Vendor Verified, Uncoordinated Disclosure, Discovered in the Wild

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.

Products

Microsoft Corporation

Windows

XP SP2
ME
XP Pro x64
2003 Server
98 SE
2003 Server x64
2003 Server SP1
98
XP SP1
2000 SP4
2003 Server for Itanium SP1
2003 Server for Itanium

References

Credit

  • Dan Hubbard -


Direct URL: http://osvdb.org/21987