CVE-2006-5586
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 2.9%
from disclosure to weapon4 days
Published on NVDApr 4
1st PoC+4d
exploitation probability
2.9%top 14% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
The Graphics Rendering Engine in Microsoft Windows 2000 SP4 and XP SP2 allows local users to gain privileges via "invalid application window sizes" in layered application windows, aka the "GDI Invalid Window Size Elevation of Privilege Vulnerability."
Affected products
n/a · n/apublic PoCs found — 3✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/3688exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/3755exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/3804⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-017https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1385http://www.securityfocus.com/archive/1/466186/100/200/threadedhttp://www.securityfocus.com/bid/23277http://www.securitytracker.com/id?1017846http://www.vupen.com/english/advisories/2007/1215