vendor:
Windows
by:
ATmaCA
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Windows
Affected Version From: Windows
Affected Version To: Windows XP SP1
Patch Exists: YES
Related CWE: CVE-2004-0209
CPE: o:microsoft:windows
Platforms Tested: Windows
2004
Windows JPEG GDI+ Overflow Download Shellcoded Exploit (MS04-028)
This is a shellcoded exploit for the Windows JPEG GDI+ Overflow vulnerability (MS04-028). It is a generic win32 http download shellcode that can be used to download and execute arbitrary code on a vulnerable system. The shellcode is designed to avoid the end of jpeg image marker (0xFFh 0xD9) and has a size of approximately 2500 bytes.
Mitigation:
Apply the official patch provided by Microsoft for the MS04-028 vulnerability. Disable or remove the affected component if not required.