Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Cyanid-E

#53173de 53,638
2.6CVSS total
Vulnerabilidades · 1
PT-2006-4915
2.6
2006-08-10
Microsoft · Windows · CVE-2006-4071
**Name of the Vulnerable Software and Affected Versions** Microsoft Windows versions prior to the fixed version **Description** The issue is related to a sign extension vulnerability in the createBrushIndirect function within the GDI library (gdi32.dll). This vulnerability allows user-assisted attackers to cause a denial of service, resulting in an application crash, by using a crafted WMF file. **Recommendations** For Microsoft Windows versions prior to the fixed version, update to the latest version to resolve the issue. As a temporary workaround, consider restricting the use of WMF files to minimize the risk of exploitation.