CVE-2004-1049
EXPLOITEDMicrosoft Windows - Remote Code Execution via Malformed Image File
Title source: llmExploitation Summary
CVE-2004-1049 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon Format Handling Vulnerability."
References (16)
Core 16
Core References
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/13645
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3220
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3097
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-002
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2956
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=110382891718076&w=2
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1012684
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/18668
Third Party Advisory, US Government Resource third-party-advisory
government-resource
x_refsource_ciac
http://www.ciac.org/ciac/bulletins/p-094.shtml
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3355
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/12095
Exploit x_refsource_misc
http://www.xfocus.net/flashsky/icoExp/index.html
Third Party Advisory, US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA05-012A.html
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4671
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/12623
Third Party Advisory, US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/625856
Scores
EPSS
0.3058
EPSS Percentile
98.1%
Details
VulnCheck KEV
2010-05-01
Status
published
Products (4)
microsoft/windows_2000
(5 CPE variants)
microsoft/windows_2003_server
r2
microsoft/windows_nt
microsoft/windows_xp
(2 CPE variants)
Published
Dec 31, 2004
Tracked Since
Feb 18, 2026