7.2

CVE-2006-5758

Exploit
The Graphics Rendering Engine in Microsoft Windows 2000 through 2000 SP4 and Windows XP through SP2 maps GDI Kernel structures on a global shared memory section that is mapped with read-only permissions, but can be remapped by other processes as read-write, which allows local users to cause a denial of service (memory corruption and crash) and gain privileges by modifying the kernel structures.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2000 Update sp4
Microsoft ≫ Windows Xp Update gold Edition professional_x64
Microsoft ≫ Windows Xp Update sp2
Microsoft ≫ Windows Xp Update sp2 Edition professional_x64
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.37% 0.93
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://kernelwars.blogspot.com/2007/01/alive.html
http://www.blackhat.com/html/bh-europe-07/bh-eu-07-speakers.html#Eriksson
http://projects.info-pull.com/mokb/MOKB-06-11-2006.html
http://secunia.com/advisories/22668
Vendor Advisory
http://securitytracker.com/id?1017168
http://www.securityfocus.com/archive/1/466186/100/200/threaded
http://www.securityfocus.com/bid/20940
Exploit
http://www.vupen.com/english/advisories/2006/4358
Vendor Advisory
http://www.vupen.com/english/advisories/2007/1215
Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-017
https://exchange.xforce.ibmcloud.com/vulnerabilities/30042
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2056