CVE-2004-1049
Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 30.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon Format Handling Vulnerability."
- CVSS 2.0
- 5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
- EPSS
- 30.58% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 2000 · microsoft/windows 2003 server · microsoft/windows nt · microsoft/windows xp
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=110382891718076&w=2
- http://secunia.com/advisories/13645
- http://securitytracker.com/id?1012684
- http://www.ciac.org/ciac/bulletins/p-094.shtml
- http://www.kb.cert.org/vuls/id/625856Third Party Advisory, US Government Resource
- http://www.osvdb.org/12623
- http://www.securityfocus.com/bid/12095
- http://www.us-cert.gov/cas/techalerts/TA05-012A.htmlThird Party Advisory, US Government Resource
- http://www.xfocus.net/flashsky/icoExp/index.htmlExploit
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-002
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18668
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2956
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3097
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3220
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3355
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4671
- http://marc.info/?l=bugtraq&m=110382891718076&w=2
- http://secunia.com/advisories/13645
- http://securitytracker.com/id?1012684
- http://www.ciac.org/ciac/bulletins/p-094.shtml
- http://www.kb.cert.org/vuls/id/625856Third Party Advisory, US Government Resource
- http://www.osvdb.org/12623
- http://www.securityfocus.com/bid/12095
- http://www.us-cert.gov/cas/techalerts/TA05-012A.htmlThird Party Advisory, US Government Resource
- http://www.xfocus.net/flashsky/icoExp/index.htmlExploit
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-002
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18668
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2956
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3097
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3220
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.