Lucene search

K
cve[email protected]CVE-2006-5758
HistoryNov 06, 2006 - 8:07 p.m.

CVE-2006-5758

2006-11-0620:07:00
CWE-119
web.nvd.nist.gov
31
cve-2006-5758
microsoft windows
graphics rendering engine
denial of service
memory corruption
privilege escalation

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.2 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.0%

The Graphics Rendering Engine in Microsoft Windows 2000 through 2000 SP4 and Windows XP through SP2 maps GDI Kernel structures on a global shared memory section that is mapped with read-only permissions, but can be remapped by other processes as read-write, which allows local users to cause a denial of service (memory corruption and crash) and gain privileges by modifying the kernel structures.

Affected configurations

NVD
Node
microsoftwindows_2000sp4
OR
microsoftwindows_xpgoldprofessional_x64
OR
microsoftwindows_xpsp2
OR
microsoftwindows_xpsp2professional_x64

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.2 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.0%