peter bassill · operator
$ cve CVE-2006-5586 JSON

CVE-2006-5586 EXPLOIT

7.2
HIGH · CVSS 2.0 · EPSS 2.9% (pctl 86)

Patch early

A public exploit exists.

Description

The Graphics Rendering Engine in Microsoft Windows 2000 SP4 and XP SP2 allows local users to gain privileges via "invalid application window sizes" in layered application windows, aka the "GDI Invalid Window Size Elevation of Privilege Vulnerability."

Scoring

CVSS7.2 (HIGH, v2.0)
VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS2.88% — more likely to be exploited than 86% of all CVEs
On CISA KEVno
Public exploityes
Published2007-04-04
Last modified2026-06-16

Affected (2)

VendorProduct
microsoftwindows 2000
microsoftwindows xp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD