← Back to browse · API

CVE-2008-1083

Severity
HIGH
CVSS
8.1
EPSS
0.57102
Risk score
52.39
CISA KEV
No
PoC
No
Published
2008-04-08
Modified
2024-10-15
First seen
2026-08-07
Aliases
EUVD-2008-1094, GHSA-8PGM-3M7V-29VC
Products
n/a:n/a n/a
Sources
euvd EUVD-2008-1094

Description

Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF or WMF image file with a malformed header that triggers an integer overflow, aka "GDI Heap Overflow Vulnerability."

References