CVE-2004-0209

Microsoft Windows 2000, Windows XP, and Windows Server 2003 - Remote Code Execution via WMF/EMF Image Processing

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-0209. PoCs published by houseofdabus.

AI-analyzed exploit summary This exploit targets a heap overflow vulnerability in Microsoft Windows XP's graphics rendering engine (CVE-2004-0209) via a malicious EMF file. It includes shellcode for port binding or downloading/executing a payload, triggered by viewing the file or thumbnail.

Description

Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer."

Exploits (1)

exploitdb WORKING POC VERIFIED
by houseofdabus · cremotewindows_x86
https://www.exploit-db.com/exploits/584

This exploit targets a heap overflow vulnerability in Microsoft Windows XP's graphics rendering engine (CVE-2004-0209) via a malicious EMF file. It includes shellcode for port binding or downloading/executing a payload, triggered by viewing the file or thumbnail.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Windows XP SP1 (Graphics Rendering Engine)
No auth needed
Prerequisites: Victim must open or preview the malicious EMF file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11375
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16581
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/806278
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=109829067325779&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17658
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1872
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2428
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2114

Scores

EPSS 0.6205
EPSS Percentile 99.1%

Details

Status published
Products (3)
microsoft/windows_2000
microsoft/windows_2003_server r2
microsoft/windows_xp
Published Nov 03, 2004
Tracked Since Feb 18, 2026