Vulnerability Name: | CVE-2006-5586 (CCN-33261) | ||||||||
Assigned: | 2006-10-27 | ||||||||
Published: | 2007-04-03 | ||||||||
Updated: | 2018-10-17 | ||||||||
Summary: | The Graphics Rendering Engine in Microsoft Windows 2000 SP4 and XP SP2 allows local users to gain privileges via "invalid application window sizes" in layered application windows, aka the "GDI Invalid Window Size Elevation of Privilege Vulnerability." | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-5586 Source: CCN Type: SECTRACK ID: 1017846 Windows Kernel GDI Input Validation Flaw in Processing Application Size Parameters Lets Local Users Gain System Privileges Source: CCN Type: ASA-2007-140 MS07-17 Vulnerabilities in GDI Could Allow Remote Code Execution (925902) Source: CCN Type: Microsoft Security Bulletin MS07-017 Vulnerabilities in GDI Could Allow Remote Code Execution (925902) Source: HP Type: UNKNOWN HPSBST02206 Source: BID Type: UNKNOWN 23277 Source: CCN Type: BID-23277 Microsoft Windows GDI Invalid Window Size Local Privilege Escalation Vulnerability Source: SECTRACK Type: UNKNOWN 1017846 Source: VUPEN Type: UNKNOWN ADV-2007-1215 Source: MS Type: UNKNOWN MS07-017 Source: XF Type: UNKNOWN win-gdi-size-privilege-escalation(33261) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1385 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |