Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2004-0209Microsoft Windows 2003 Server vulnerability

4 documents4 sources
Severity
10.0CRITICALNVD
EPSS
69.6%
top 1.34%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedNov 3
Latest updateApr 29

Description

Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer."

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-cxqv-7f9g-p3wr: Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attacker2022-04-29
CVEList
CVE-2004-0209: Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attacker2004-10-16

💥Exploits & PoCs

1
Exploit-DB
Microsoft Windows (x86) - Metafile '.emf' Heap Overflow (MS04-032)2004-10-20
CVE-2004-0209 — Microsoft vulnerability | cvebase