Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2006-5586 | First vendor Publication | 2007-04-04 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 7.2 | Attack Range | Local |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The Graphics Rendering Engine in Microsoft Windows 2000 SP4 and XP SP2 allows local users to gain privileges via "invalid application window sizes" in layered application windows, aka the "GDI Invalid Window Size Elevation of Privilege Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5586 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:1385 | |||
Oval ID: | oval:org.mitre.oval:def:1385 | ||
Title: | GDI Invalid Window Size Elevation of Privilege Vulnerability | ||
Description: | The Graphics Rendering Engine in Microsoft Windows 2000 SP4 and XP SP2 allows local users to gain privileges via "invalid application window sizes" in layered application windows, aka the "GDI Invalid Window Size Elevation of Privilege Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2006-5586 | Version: | 3 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows XP | Product(s): | |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Os | 1 | |
Os | 3 |
ExploitDB Exploits
id | Description |
---|---|
2010-09-20 | Windows ANI LoadAniIcon() Chunk Size Stack Buffer Overflow (SMTP) |
2010-08-12 | Windows ANI LoadAniIcon() Chunk Size Stack Buffer Overflow (HTTP) |
2007-04-26 | MS Windows (.ANI) GDI Remote Elevation of Privilege Exploit (MS07-017) |
2007-04-17 | MS Windows GDI - Local Privilege Escalation Exploit (MS07-017) (2) |
2007-04-08 | MS Windows GDI - Local Privilege Escalation Exploit (MS07-017) |
OpenVAS Exploits
Date | Description |
---|---|
2011-01-14 | Name : Vulnerabilities in GDI Could Allow Remote Code Execution (925902) File : nvt/gb_ms07-017.nasl |
2010-07-08 | Name : Microsoft Windows GDI Multiple Vulnerabilities (925902) File : nvt/ms07-017.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
34096 | Microsoft Windows GDI Invalid Window Size Local Privilege Escalation |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2007-04-03 | IAVM : 2007-A-0020 - Multiple Vulnerabilities in Microsoft Windows GDI Severity : Category I - VMSKEY : V0013883 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Microsoft Internet Explorer ANI file parsing buffer overflow attempt RuleID : 3079-community - Revision : 25 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer ANI file parsing buffer overflow attempt RuleID : 3079 - Revision : 25 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer ani file processing - remote code execution attempt RuleID : 19886 - Revision : 5 - Type : BROWSER-IE |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2007-04-03 | Name : Arbitrary code can be executed on the remote host through the email client or... File : smb_nt_ms07-017.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:17:46 |
|
2024-11-28 12:10:25 |
|
2021-05-04 12:04:47 |
|
2021-04-22 01:05:23 |
|
2020-05-23 00:18:37 |
|
2018-10-18 00:19:46 |
|
2018-10-13 00:22:35 |
|
2017-10-11 09:23:46 |
|
2016-04-26 15:14:23 |
|
2014-02-17 10:37:43 |
|
2013-11-11 12:37:37 |
|
2013-05-11 11:13:12 |
|