Windows Metafile (WMF) SetAbortProc() Code Execution [012]

Strike ID:
E05-3io10
CVSS:
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
False Positive:
f
Variants:
1
Year:
2005

Description

This strike exploits a vulnerability in the GDI library included with Windows XP, 2003, and Vista. This vulnerability uses the 'Escape' metafile function to execute arbitrary code through the SetAbortProc procedure.

CVE

Bid