CVE-2009-1217

Microsoft Gdi+ - Denial of Service

Title source: rule
STIX 2.1

Description

Off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP allows remote attackers to cause a denial of service (stack corruption and application termination) via a crafted EMF file that triggers an integer overflow, as demonstrated by voltage-exploit.emf, aka the "Microsoft GdiPlus EMF GpFont.SetData integer overflow."

Exploits (1)

exploitdb WRITEUP VERIFIED
by Black Security · textdoswindows
https://www.exploit-db.com/exploits/8281

Scores

EPSS 0.5639
EPSS Percentile 98.1%

Details

CWE
CWE-193
Status published
Products (1)
microsoft/gdi\+
Published Apr 01, 2009
Tracked Since Feb 18, 2026