CVE-2010-0028

EXPLOITED

Microsoft Windows 2000 - Numeric Error

Title source: rule

Description

Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted JPEG (.JPG) file, aka "MS Paint Integer Overflow Vulnerability."

Exploits (1)

exploitdb WORKING POC VERIFIED
by unsign · perldoswindows
https://www.exploit-db.com/exploits/12518

Scores

EPSS 0.6924
EPSS Percentile 98.7%

Details

VulnCheck KEV 2012-10-18
CWE
CWE-189
Status published
Products (3)
microsoft/windows_2000
microsoft/windows_server_2003
microsoft/windows_xp (3 CPE variants)
Published Feb 10, 2010
Tracked Since Feb 18, 2026