CVE-2009-1217
Off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP allows remote attackers to cause a denial of service (stack corruption and application termination) via a crafted EMF file that triggers an integer overflow,…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.3%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP allows remote attackers to cause a denial of service (stack corruption and application termination) via a crafted EMF file that triggers an integer overflow, as demonstrated by voltage-exploit.emf, aka the "Microsoft GdiPlus EMF GpFont.SetData integer overflow."
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
- EPSS
- 16.33% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-193
- Affected
- microsoft/gdi\+
- Source
- cve@mitre.org
References
- http://bl4cksecurity.blogspot.com/2009/03/microsoft-gdiplus-emf-gpfontsetdata.htmlBroken Link
- http://blogs.technet.com/srd/archive/2009/03/26/new-emf-gdiplus-dll-crash-not-exploitable-for-code-execution.aspxBroken Link
- http://www.securityfocus.com/bid/34250Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2009/0832Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49438Third Party Advisory, VDB Entry
- http://bl4cksecurity.blogspot.com/2009/03/microsoft-gdiplus-emf-gpfontsetdata.htmlBroken Link
- http://blogs.technet.com/srd/archive/2009/03/26/new-emf-gdiplus-dll-crash-not-exploitable-for-code-execution.aspxBroken Link
- http://www.securityfocus.com/bid/34250Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2009/0832Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49438Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.