CVE-2006-0020Microsoft Windows 2003 Server vulnerability

3 documents3 sources
Severity
9.3CRITICALNVD
CNA7.5
EPSS
35.2%
top 2.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateMay 1

Description

An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-37h2-23m8-m8pm: An unspecified Microsoft WMF parsing application, as used in Internet Explorer 52022-05-01
CVEList
CVE-2006-0020: An unspecified Microsoft WMF parsing application, as used in Internet Explorer 52006-01-10