CVE-2006-5586 describes a local privilege escalation vulnerability in the Graphics Rendering Engine of Microsoft Windows 2000 SP4 and XP SP2. This flaw, dubbed the "GDI Invalid Window Size Elevation of Privilege Vulnerability," allows local users to gain elevated privileges by manipulating invalid application window sizes in layered application windows. With a CVSS score of 7.2, it represents a high-severity issue where an attacker with local access can achieve full compromise (confidentiality, integrity, and availability). While there is no evidence of active exploitation in the wild or Metasploit modules, several ExploitDB entries related to GDI privilege escalation (MS07-017) suggest potential exploitability, though direct correlation to CVE-2006-5586 is not explicitly stated. Community discussion and media coverage for this specific CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_xp:*:gold:professional_x64:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_xp:*:sp2:professional_x64:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.