vendor:
Windows XP
by:
John Smith, Evil Fingers
7.5
CVSS
HIGH
GDI+ Vulnerability
CWE
Product Name: Windows XP
Affected Version From: Windows XP SP2
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2
GDI+ Vulnerability
This exploit targets a vulnerability in the Gdiplus.dll library in Windows XP SP2. It allows an attacker to execute arbitrary code or cause a denial of service by tricking the user into opening a specially crafted GIF file.
Mitigation:
Apply the latest patches and updates from the vendor. Avoid opening GIF files from untrusted sources.