CVE-2005-0803
The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 67.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be used, aka "Enhanced Metafile Vulnerability."
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 67.69% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- microsoft/windows 2000
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=111108743527497&w=2
- http://secunia.com/advisories/14631
- http://secunia.com/advisories/17223Vendor Advisory
- http://secunia.com/advisories/17461Vendor Advisory
- http://securitytracker.com/id?1015168
- http://support.avaya.com/elmodocs2/security/ASA-2005-228.pdf
- http://www.kb.cert.org/vuls/id/134756US Government Resource
- http://www.osvdb.org/20580
- http://www.securityfocus.com/bid/12834Exploit
- http://www.us-cert.gov/cas/techalerts/TA05-312A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2005/2348Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-053
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19727
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1121
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1152
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1215
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1240
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A671
- http://marc.info/?l=bugtraq&m=111108743527497&w=2
- http://secunia.com/advisories/14631
- http://secunia.com/advisories/17223Vendor Advisory
- http://secunia.com/advisories/17461Vendor Advisory
- http://securitytracker.com/id?1015168
- http://support.avaya.com/elmodocs2/security/ASA-2005-228.pdf
- http://www.kb.cert.org/vuls/id/134756US Government Resource
- http://www.osvdb.org/20580
- http://www.securityfocus.com/bid/12834Exploit
- http://www.us-cert.gov/cas/techalerts/TA05-312A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2005/2348Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-053
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.