Vulnerability record · CVE-2005-0803 · published 2 May 2005
CVE-2005-0803: Windows 2000 GDI32 EMF palette offset denial of service
Microsoft · Windows 2000
The GetEnhMetaFilePaletteEntries API in GDI32.DLL on Windows 2000 mishandles crafted Enhanced Metafile (EMF) files that supply invalid end, emreof, or palent offsets. Processing such a file crashes the affected application, giving a remote denial-of-service condition. The record covers only Windows 2000 and does not list specific affected builds or patch levels.
Description
The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be used, aka "Enhanced Metafile Vulnerability."
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityAvailability-only impact on a legacy, unsupported platform, but remote unauthenticated reach and a high EPSS score keep it relevant where Windows 2000 persists.
What it is
The GetEnhMetaFilePaletteEntries API in GDI32.DLL on Windows 2000 mishandles crafted Enhanced Metafile (EMF) files that supply invalid end, emreof, or palent offsets. Processing such a file crashes the affected application, giving a remote denial-of-service condition. The record covers only Windows 2000 and does not list specific affected builds or patch levels.
Impact
An attacker can crash an application that parses the malformed EMF, disrupting availability for the user or service. The flaw is availability-only; no confidentiality or integrity impact is described.
Attack surface
Reached remotely over the network by delivering a crafted EMF file to a vulnerable application that calls the GDI32 palette API. The CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required, though the file must still reach a parsing application.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented. EPSS is high (0.67689, 99.28th percentile) and one reference carries an Exploit tag, but the record does not confirm public exploit code or in-the-wild activity.
What to do
- Apply the Microsoft security update referenced in MS05-053 for Windows 2000 systems.
- Retire or isolate remaining Windows 2000 hosts, which no longer receive current security fixes.
- Block or filter untrusted EMF files at mail gateways, web proxies, and file-transfer paths.
- Restrict which applications and users can open EMF content from external sources.
- Monitor vendor advisories for any backported fixes if Windows 2000 must remain in use.
Detection
- Alert on application crashes or faults in GDI32.DLL or the GetEnhMetaFilePaletteEntries path.
- Hunt for EMF files with malformed or out-of-range end, emreof, or palent offsets arriving from external sources.
- Correlate crash telemetry with recent receipt or opening of EMF attachments or downloads.
- Review Windows 2000 host logs for repeated application termination events tied to image or metafile processing.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-0803 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-0803), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.