Internet Security Software - Computer Security Software - Security Software
Software Security Solutions background
 
 

mountains

LinkScanner Knowledge Base


spacer

Exploit: Windows Metafile WMF SetAbortProc (CVE-2005-4560)

Dated Posted:

04.10.2007

Posted By:

Roger Thompson - CTO

Category:

Research

 
 

An obscure and rarely used function in Microsoft's Windows MetaFile specification, SetAbortProc, can be used to create a WMF that when interpreted will execute code implanted by the malicious exploiter. This means that rendering a maliciously designed WMF file, even via a thumbnail view, can allow uninvited embedded program code execution.

Though this vector has been in place since Windows 3.1 days, it is exploitable only on Windows NT-based systems. This was first reported around 28 December, 2005, with exploit code turning up on web sites within hours of the initial report. Microsoft issued an emergency patch for this problem on 5 January, 2006 - (MSO6-001). Speculation that this security hole was a deliberate backdoor into Windows has been throughly discredited.

(CVE-2005-4560)

 

Return to Knowledge Base

Anti Virus Software | Eset NOD32 | Kaspersky | Eset Smart Security | Spyware Removal Software | Spysweeper
Remove Adware |LinkScanner | LinkScanner Online | Firewalls | Outpost | SonicWALL | Disaster Recovery
Spam Blocker
| Security Tools | Computer Security Tips | Layered Security Model | Security Software Resources
Solution Certifications | Trusted Reviews | Security Goal | Security Links
Partners | Press Releases | White Papers | About Us Home


Contact Software Security Solutions at (303) 232-9070
Site Map | Privacy Policy | Legal Notice | Home

© 2008 Software Security Solutions. All rights reserved.