9.3
CVSSv2

CVE-2008-1083

Published: 08/04/2008 Updated: 07/12/2023
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 945
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote malicious users to execute arbitrary code via an EMF or WMF image file with a malformed header that triggers an integer overflow, aka "GDI Heap Overflow Vulnerability."

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows server 2008 -

microsoft windows 2003 server

microsoft windows xp

microsoft windows vista

microsoft windows 2000

microsoft windows vista -

Exploits

///////////////////////////////////////////////////////////// ///Exploit the MS08-021 : Stack Overflow on GDI API ///Author: Lamhtz ///Date: April 14th, 2008 ///Usage: <appnameexe> [filename] ///Function: Generate a crafted emf file which could /// automatically run calcexe in Win2kSP4 CHS Version /// with MS07-046 patched but ...
CreateDIBPatternBrushPt Heap Overflow DOS By Ac!dDrop This was tested on Windows XP Sp2 GDI32dll 5126003099 Internet explorer 6029002180 ------ Causes Explorerexe to crash and causes Internet explorer to close silently ------ This is work in progress , i am still trying to make it run arbitary code githubcom/offensiv ...
EMR_COLORMATCHTOTARGETW stack buffer overflow exploit By Ac!dDrop This is one of the 2 Vulnerabilities of MS08-021 Tested on Windows xp professional SP1 GDi32dll 5126001106 kernel32dll 5126001106 ws2_32dll 5126000 calczip---> executes calculator IEzip and localhostzip ------> connects at localhost at port 230 On Wind ...