CVE-2010-0028
Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted JPEG (.JPG) file, aka "MS Paint Integer Overflow Vulnerability."
- Affected products
- Paint, Windows, Windows 2000, Windows Server 2003, Windows Xp
- Microsoft Windows 2000
- All versions
- Microsoft Windows Server 2003
- All versions
- Microsoft Windows Xp
- All versions
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 48.5% (99th percentile)
- Weakness
- CWE-189
- NVD status
- Modified
- Published
- 2010-02-10
CVE-2010-0028 at NVD
3 known exploits for CVE-2010-0028
Proof-of-concept code and exploit modules indexed by Sploitus