vendor:
Windows
by:
Hong Gil-Dong & Chun Woo-Chi
7.5
CVSS
HIGH
Integer Overflow
Integer Overflow
CWE
Product Name: Windows
Affected Version From: 5.1.2600.3099
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2 Korean Edition
2007
MS07-046(GDI32.dll Integer overflow DOS) Proof Of Concept Code
This Proof of Concept (POC) code demonstrates an integer overflow vulnerability in the GDI32.dll library, which can cause a denial of service (DOS) condition. When an application reads a malformed Windows Meta File (WMF) like this POC, it crashes. By applying this code, an attacker can execute arbitrary code.
Mitigation:
Apply the relevant security patch provided by the vendor.