Skip to main content

CVE-2008-1083

8.1
HIGHCVSS v3.1 Base Score
50.36%
MEDIUM RiskEPSS (98th percentile)

Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF or WMF image file with a malformed header that triggers an integer overflow, aka "GDI Heap Overflow Vulnerability."

Published: 4/8/2008
Modified: 4/9/2025
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

50.36%MEDIUM Exploitation Risk
98th percentile

This vulnerability has a 50.36% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.

Related Vulnerabilities