Description
Off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP allows remote attackers to cause a denial of service (stack corruption and application termination) via a crafted EMF file that triggers an integer overflow, as demonstrated by voltage-exploit.emf, aka the "Microsoft GdiPlus EMF GpFont.SetData integer overflow."
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Black Security · textdoswindows
https://www.exploit-db.com/exploits/8281
References (5)
Scores
EPSS
0.5639
EPSS Percentile
98.1%
Details
CWE
CWE-193
Status
published
Products (1)
microsoft/gdi\+
Published
Apr 01, 2009
Tracked Since
Feb 18, 2026