CVE-2007-3034

Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 - Remote Code Execution via Crafted Metafile

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-3034. PoCs published by Gil-Dong / Woo-Chi.

AI-analyzed exploit summary This PoC exploits an integer overflow in GDI32.dll via a malformed WMF file, causing a DoS. The code generates a malicious WMF file and triggers the vulnerability using Windows API calls.

Description

Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted metafile (image) with a large record length value, which triggers a heap-based buffer overflow.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Gil-Dong / Woo-Chi · cdoswindows
https://www.exploit-db.com/exploits/4337

This PoC exploits an integer overflow in GDI32.dll via a malformed WMF file, causing a DoS. The code generates a malicious WMF file and triggers the vulnerability using Windows API calls.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Windows (GDI32.dll, tested on Windows XP SP2)
No auth needed
Prerequisites: Ability to deliver a malicious WMF file to the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/476505/100/0/threaded
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA07-226A.html
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/640136
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26423
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018563
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/25302
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2870
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2088

Scores

EPSS 0.5475
EPSS Percentile 98.9%

Details

CWE
CWE-189
Status published
Products (4)
microsoft/windows_2000
microsoft/windows_2003_server (2 CPE variants)
microsoft/windows_server_2003
microsoft/windows_xp (2 CPE variants)
Published Aug 14, 2007
Tracked Since Feb 18, 2026