Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF or WMF image file with a malformed header that triggers an integer overflow, aka "GDI Heap Overflow Vulnerability."
History

Tue, 15 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published: 2008-04-08T23:00:00

Updated: 2024-10-15T14:22:20.263Z

Reserved: 2008-02-28T00:00:00

Link: CVE-2008-1083

cve-icon Vulnrichment

Updated: 2024-08-07T08:08:57.598Z

cve-icon NVD

Status : Modified

Published: 2008-04-08T23:05:00.000

Modified: 2024-10-15T15:35:03.827

Link: CVE-2008-1083

cve-icon Redhat

No data.