vendor:
Windows XP
by:
Elia Florio
7.5
CVSS
HIGH
Heap Overflow
119
CWE
Product Name: Windows XP
Affected Version From: Windows XP Professional English SP1 - GDIPLUS.DLL version 5.1.3097.0
Affected Version To: Windows XP Professional Italian SP1 - GDIPLUS.DLL version 5.1.3101.0
Patch Exists: YES
Related CWE: CVE-2004-0200
CPE: o:microsoft:windows_xp
Platforms Tested: Windows XP
2004
MS04-028 Exploit PoC II with Shellcode: CreateUser X in Administrators Group
This exploit triggers a heap overflow vulnerability in the GDIPLUS.DLL file on Windows XP systems. By creating a crafted JPEG file, an attacker can execute arbitrary code with elevated privileges, creating a new user in the Administrators group. The exploit has been tested on Windows XP Professional English SP1 (GDIPLUS.DLL version 5.1.3097.0) and Windows XP Professional Italian SP1 (GDIPLUS.DLL version 5.1.3101.0). Note that Windows XP SP2 is not vulnerable to this exploit.
Mitigation:
Apply the security patches provided by Microsoft for the affected versions of Windows XP. Upgrade to a supported and more secure operating system.