Vulnerability record · CVE-2005-4560 · published 28 December 2005
CVE-2005-4560: Windows GDI32 WMF SETABORTPROC escape code execution
Microsoft · Windows 2003 Server
Microsoft Windows GDI32.DLL fails to properly validate a crafted SETABORTPROC GDI Escape function call inside a Windows Metafile (WMF) image, allowing arbitrary code execution. The flaw was originally found exploited in the wild and affects the Windows Picture and Fax Viewer (SHIMGVW.DLL) rendering path. It matters because a malformed image can run attacker code in the context of the viewing user.
Description
The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote unauthenticated code execution with public exploit references and very high EPSS, though it is not in KEV and affects only legacy Windows versions.
What it is
Microsoft Windows GDI32.DLL fails to properly validate a crafted SETABORTPROC GDI Escape function call inside a Windows Metafile (WMF) image, allowing arbitrary code execution. The flaw was originally found exploited in the wild and affects the Windows Picture and Fax Viewer (SHIMGVW.DLL) rendering path. It matters because a malformed image can run attacker code in the context of the viewing user.
Impact
An attacker gains arbitrary code execution with the privileges of the user or process that renders the malicious WMF file. On Windows XP and Windows 2003 Server this can lead to full system compromise depending on the victim's rights.
Attack surface
Reached remotely over the network with no authentication required (CVSS 2.0 vector AV:N/AC:L/Au:N), typically by delivering a crafted WMF image that the victim opens or previews. User interaction is implied by the need to view or render the image, though the vector itself does not encode it.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.86093, 99.72nd percentile) and multiple references carry Exploit tags, indicating public exploit material and active interest. The description states it was originally discovered in the wild.
What to do
- Apply the Microsoft security update referenced in advisory 912840 (MS06-001) to affected Windows XP and Windows 2003 Server systems.
- Disable or restrict WMF rendering in Windows Picture and Fax Viewer and other applications that process WMF files until patching is complete.
- Block or strip WMF attachments and image files at email and web gateways.
- Unregister or restrict the shimgvw.dll handler where operationally feasible.
- Monitor vendor advisories from Microsoft, Secunia and US-CERT for updated guidance.
Detection
- Hunt for WMF files containing SETABORTPROC escape records in email attachments, web downloads and file shares.
- Alert on shimgvw.dll or GDI32.DLL loading in unexpected processes or spawning child processes.
- Monitor for process creation from image-viewing applications that then launch scripting or command interpreters.
- Review proxy and mail logs for WMF content delivered from untrusted external sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-4560 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-4560), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.