TUCoPS :: Windows :: b06-2991.htm

Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution

SYMSA-2006-004: Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution

Hash: SHA1=0D
                     Symantec Vulnerability Research=0D 
                           Security Advisory=0D
Advisory ID   : SYMSA-2006-004=0D
Advisory Title: Vulnerability in Graphics Rendering Engine Could=0D
                Allow Remote Code Execution=0D
Author : Peter Ferrie / 
Release Date  : 06-13-2006=0D
Application   : Those which utilize the vulnerable function on=0D
                affected platforms=0D
Platform      : Windows 98, Windows 98 Second Edition, Windows=0D
                Millennium Edition=0D
Severity      : Remotely exploitable arbitrary code execution=0D
Vendor status : Vendor verified, patch available (See MS06-026=0D
                and KB918547)=0D
CVE Number    : CVE-2006-2376=0D
Reference : 
        A remote code execution vulnerability exists in the=0D
        Graphics Rendering Engine because of the way that it=0D
        handles Windows Metafile (WMF) images.=0D
        An attacker could exploit this by placing a specially=0D
        crafted WMF or EMF image on a webpage, or by sending=0D
        the image as an attachment in an e-mail.  The exploit=0D
        is triggered by viewing the specially crafted image=0D
        file.  No user interaction is required.=0D
        An attacker who successfully exploited this vulnerability=0D
        could take complete control of the affected system.=0D
        A heap overflow vulnerability exists in the WMF=0D
        PolyPolygon function, because of an unchecked user-=0D
        supplied parameter.=0D
=0D =0D The manner of the heap corruption is under user control,=0D which can result in the execution of arbitrary code.=0D =0D =0D Vendor Response:=0D =0D The above vulnerability was addressed for the affected=0D platforms via Microsoft Security Bulletin MS06-026. If=0D there are any further questions about this statement,=0D please contact =0D =0D Recommendation:=0D =0D Follow your organization's testing procedures before=0D applying patches or workarounds. Customers should apply=0D Microsoft's update as soon as possible.=0D =0D =0D Common Vulnerabilities and Exposures (CVE) Information:=0D =0D The Common Vulnerabilities and Exposures (CVE) project has assigned=0D the following names to these issues. These are candidates for=0D inclusion in the CVE list (, which standardizes=0D names for security problems.=0D =0D =0D CVE-2006-2376

