vendor:
MS Paint
by:
Unknown
7.5
CVSS
HIGH
Integer Overflow
Integer Overflow
CWE
Product Name: MS Paint
Affected Version From: 5.1.2600.2180
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2010-1234
CPE: a:microsoft:paint:5.1.2600.2180
Platforms Tested: Windows XP SP2
2010
MS Paint Integer Overflow Vulnerability
This exploit triggers a crash in MS Paint due to an integer overflow vulnerability. The exploit code is written in Perl and it sends a specially crafted image file to the target. When MS Paint tries to open the image, it crashes.
Mitigation:
The vendor has released a patch to fix this vulnerability. Users are advised to update their software to the latest version.