CVE-2007-2237
MEDIUMMicrosoft Windows XP - Denial of Service via ICO File with Zero Height
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-2237. PoCs published by Kad, Dennis Rand.
AI-analyzed exploit summary This is a writeup describing a Microsoft GDI+ integer division by zero flaw in handling .ICO files (CVE-2007-2237). It references an external binary exploit but does not contain functional exploit code itself.
Description
Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error.
Exploits (2)
This is a writeup describing a Microsoft GDI+ integer division by zero flaw in handling .ICO files (CVE-2007-2237). It references an external binary exploit but does not contain functional exploit code itself.
The provided text describes a remote denial-of-service vulnerability in Microsoft Windows due to improper handling of maliciously crafted ICO files. Exploitation involves tricking victims into opening a malicious file, leading to DoS conditions in applications like Windows Explorer.
References (9)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H