PT-2006-6439 · Microsoft · Windows 2000+2

Cesar Cerrudo

·

Published

2006-11-06

·

Updated

2018-10-17

·

CVE-2006-5758

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Microsoft Windows versions 2000 through 2000 SP4 Microsoft Windows versions XP through SP2
Description: A privilege elevation issue exists in the Graphics Rendering Engine, allowing local users to cause a denial of service and gain privileges. This is due to the engine mapping GDI Kernel structures on a global shared memory section that can be remapped by other processes as read-write, enabling modification of kernel structures. The vulnerability could allow a logged-on user to take complete control of the system.
Recommendations: For Microsoft Windows 2000 through 2000 SP4, apply the necessary security patches to fix the Graphics Rendering Engine issue. For Microsoft Windows XP through SP2, apply the necessary security patches to fix the Graphics Rendering Engine issue.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-5758

Affected Products

Windows
Windows 2000
Windows Xp