SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2004-0200

Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a…

HIGH 9.3EPSS 49.0%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 49.0%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.

CVSS 2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
49.02% probability · 99th percentile
CISA KEV
Not listed
Affected
microsoft/.net framework · microsoft/digital image pro · microsoft/digital image suite · microsoft/excel · microsoft/frontpage · microsoft/greetings · microsoft/infopath · microsoft/office · microsoft/onenote · microsoft/outlook · microsoft/picture it · microsoft/powerpoint · microsoft/producer · microsoft/project · microsoft/publisher · microsoft/visio · microsoft/visual basic · microsoft/visual c\# · microsoft/visual c\+\+ · microsoft/visual j\# .net · +4 more
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.