Vulnerability record · CVE-2004-0200 · published 28 September 2004
CVE-2004-0200: Microsoft GDI+ JPEG parsing buffer overflow via crafted image
Microsoft · .Net Framework
The JPEG parsing engine in Microsoft GDI+ (GDIPlus.dll) contains a buffer overflow: a small JPEG COM field length is normalized to a large integer length before a memory copy. A crafted JPEG can therefore corrupt memory in any application that renders images through GDI+, which is why the flaw matters across a wide range of Microsoft products.
Description
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote, unauthenticated code execution with full impact and a high EPSS score, though exploitation requires medium complexity and user interaction and the flaw is long-published.
What it is
The JPEG parsing engine in Microsoft GDI+ (GDIPlus.dll) contains a buffer overflow: a small JPEG COM field length is normalized to a large integer length before a memory copy. A crafted JPEG can therefore corrupt memory in any application that renders images through GDI+, which is why the flaw matters across a wide range of Microsoft products.
Impact
An attacker who gets a malicious JPEG processed can execute arbitrary code in the context of the affected application or user. The CVSS 2.0 vector rates full confidentiality, integrity and availability impact.
Attack surface
Reached remotely over the network (AV:N) with no authentication (Au:N), but exploitation requires medium complexity (AC:M) and typically some form of user interaction such as opening or previewing a crafted image. The description does not specify the exact delivery path beyond a JPEG image being parsed.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is high at 0.490 (98.8th percentile), indicating elevated predicted exploitation likelihood. Reference tags are limited to US Government Resource advisories and vendor/OVAL entries; no public exploit tag is present in the record.
What to do
- Apply Microsoft security bulletin MS04-028 (the vendor fix for this issue) as the first action.
- Update all affected Microsoft products listed in the record, including Office, Visual Studio, .NET Framework and Digital Image products, since GDI+ is shared.
- Block or strip untrusted JPEG attachments and image content at mail and web gateways where feasible.
- Reduce exposure by disabling or restricting automatic image preview and thumbnail generation for untrusted files.
- Track remaining unpatched GDI+-dependent applications and treat them as high risk until updated.
Detection
- Monitor for crashes or abnormal process terminations in applications that parse JPEGs (Office, browsers, image viewers) on endpoints.
- Hunt for suspicious child processes spawned by image-viewing or Office applications, which can indicate code execution after image parsing.
- Inspect mail and web proxy logs for JPEG attachments or downloads from untrusted sources delivered to GDI+-dependent applications.
- Use the OVAL definitions referenced in the record to check patch state on affected hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
24 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0200 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0200), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.