← Vulnerability feed

Vulnerability record · CVE-2004-0200 · published 28 September 2004

CVE-2004-0200: Microsoft GDI+ JPEG parsing buffer overflow via crafted image

Microsoft · .Net Framework

The JPEG parsing engine in Microsoft GDI+ (GDIPlus.dll) contains a buffer overflow: a small JPEG COM field length is normalized to a large integer length before a memory copy. A crafted JPEG can therefore corrupt memory in any application that renders images through GDI+, which is why the flaw matters across a wide range of Microsoft products.

9.3 CVSS 2.0 High EPSS 49% · top 1.2%
9.3CVSS 2.0 base score
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
24Affected product versions listed by NVD
32References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote, unauthenticated code execution with full impact and a high EPSS score, though exploitation requires medium complexity and user interaction and the flaw is long-published.

What it is

The JPEG parsing engine in Microsoft GDI+ (GDIPlus.dll) contains a buffer overflow: a small JPEG COM field length is normalized to a large integer length before a memory copy. A crafted JPEG can therefore corrupt memory in any application that renders images through GDI+, which is why the flaw matters across a wide range of Microsoft products.

Impact

An attacker who gets a malicious JPEG processed can execute arbitrary code in the context of the affected application or user. The CVSS 2.0 vector rates full confidentiality, integrity and availability impact.

Attack surface

Reached remotely over the network (AV:N) with no authentication (Au:N), but exploitation requires medium complexity (AC:M) and typically some form of user interaction such as opening or previewing a crafted image. The description does not specify the exact delivery path beyond a JPEG image being parsed.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is high at 0.490 (98.8th percentile), indicating elevated predicted exploitation likelihood. Reference tags are limited to US Government Resource advisories and vendor/OVAL entries; no public exploit tag is present in the record.

What to do

  • Apply Microsoft security bulletin MS04-028 (the vendor fix for this issue) as the first action.
  • Update all affected Microsoft products listed in the record, including Office, Visual Studio, .NET Framework and Digital Image products, since GDI+ is shared.
  • Block or strip untrusted JPEG attachments and image content at mail and web gateways where feasible.
  • Reduce exposure by disabling or restricting automatic image preview and thumbnail generation for untrusted files.
  • Track remaining unpatched GDI+-dependent applications and treat them as high risk until updated.

Detection

  • Monitor for crashes or abnormal process terminations in applications that parse JPEGs (Office, browsers, image viewers) on endpoints.
  • Hunt for suspicious child processes spawned by image-viewing or Office applications, which can indicate code execution after image parsing.
  • Inspect mail and web proxy logs for JPEG attachments or downloads from untrusted sources delivered to GDI+-dependent applications.
  • Use the OVAL definitions referenced in the record to check patch state on affected hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

24 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://marc.info/?l=bugtraq&m=109524346729948&w=2
http://www.kb.cert.org/vuls/id/297462 US Government Resource
http://www.us-cert.gov/cas/techalerts/TA04-260A.html US Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-028
https://exchange.xforce.ibmcloud.com/vulnerabilities/16304
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1105
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1721
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2706
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3038
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3082
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3320
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3810
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3881
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4003
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4216
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4307
http://marc.info/?l=bugtraq&m=109524346729948&w=2
http://www.kb.cert.org/vuls/id/297462 US Government Resource
http://www.us-cert.gov/cas/techalerts/TA04-260A.html US Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-028
https://exchange.xforce.ibmcloud.com/vulnerabilities/16304
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1105
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1721
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2706
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3038
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3082
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3320
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3810
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3881
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4003
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4216
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4307

Track CVE-2004-0200 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-0646Microsoft .NET Framework input validation flaw enables remote code executionCVE-2020-0646 is a critical remote code execution vulnerability in the Microsoft .NET Framework caused by improper input validation, classified as XM…KEVEPSS 99%analysed8.8CVE-2019-1297Microsoft Excel memory handling flaw allows remote code executionCVE-2019-1297 is a remote code execution vulnerability in Microsoft Excel caused by improper handling of objects in memory. An attacker who convinces…KEVEPSS 22%analysed8.8CVE-2009-0238Microsoft Excel invalid object access allows remote code executionMicrosoft Excel and related viewers (Excel 2000 through 2007, Excel Viewer, Office Compatibility Pack, and Office for Mac 2004/2008) fail to handle a…KEVEPSS 43%analysed8.8CVE-2007-0671Microsoft Excel remote code execution via malformed fileCVE-2007-0671 is an unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, that allows re…KEVEPSS 43%analysed7.8CVE-2021-42292Microsoft Excel security feature bypass via crafted fileCVE-2021-42292 is a security feature bypass in Microsoft Excel and related Office products. The record gives only a one-line description, so the exac…KEVEPSS 43%analysed7.8CVE-2020-1147Microsoft .NET Framework, SharePoint, and Visual Studio XML Deserialization RCEThe software fails to check the source markup of XML input, allowing crafted XML to trigger unsafe deserialization and remote code execution. It affe…KEVEPSS 94%analysed7.8CVE-2017-8759Microsoft .NET Framework remote code execution via malicious documentMicrosoft .NET Framework versions 2.0 through 4.7 contain a code injection flaw that lets an attacker run arbitrary code when a crafted document or a…KEVEPSS 89%analysed7.8CVE-2016-7262Microsoft Excel security feature bypass enables command executionA crafted cell in affected Microsoft Excel and Excel Viewer versions is mishandled when a user clicks it, allowing a security feature bypass that lea…KEVEPSS 58%analysed

Source: NIST National Vulnerability Database (record CVE-2004-0200), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.