CVE-2005-2123 describes multiple integer overflows in the GDI32.DLL of Windows 2000 SP4, XP SP1/SP2, and Server 2003 SP1. These flaws allow remote attackers to execute arbitrary code through crafted WMF and EMF images, leading to heap-based buffer overflows. With a CVSS score of 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P), this vulnerability is remotely exploitable with low attack complexity, potentially leading to full compromise. While not listed on the KEV catalog or having widespread community discussion, an ExploitDB entry exists for a denial-of-service variant, but no Metasploit or Nuclei modules are publicly available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2000:*:sp4:*:fr:*:*:*:* | ||
64-bitCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:64-bit:*:*:*:*:*:*:* | ||
itaniumCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:itanium:*:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:r2:*:*:*:*:*:*:* | ||
sp1CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.