Vulnerability record · CVE-2007-5348 · published 11 September 2008
CVE-2007-5348: Microsoft GDI+ gradient fill integer overflow leads to remote code execution
Microsoft · Digital Image Suite
GDI+ in a wide range of Microsoft products mishandles crafted gradient sizes in gradient fill input, causing an integer overflow that leads to a heap-based buffer overflow in GdiPlus.dll and VGX.DLL. Because the affected component is reachable through image and VML rendering, a malicious file or web page can corrupt memory and run attacker-controlled code. The flaw is known as the GDI+ VML Buffer Overrun Vulnerability.
Description
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via an image file with crafted gradient sizes in gradient fill input, which triggers a heap-based buffer overflow related to GdiPlus.dll and VGX.DLL, aka "GDI+ VML Buffer Overrun Vulnerability."
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityCVSS 9.3 and a 98.9th percentile EPSS score indicate severe, remotely reachable code execution with a high likelihood of attempted exploitation, though it is not in KEV and requires some user interaction.
What it is
GDI+ in a wide range of Microsoft products mishandles crafted gradient sizes in gradient fill input, causing an integer overflow that leads to a heap-based buffer overflow in GdiPlus.dll and VGX.DLL. Because the affected component is reachable through image and VML rendering, a malicious file or web page can corrupt memory and run attacker-controlled code. The flaw is known as the GDI+ VML Buffer Overrun Vulnerability.
Impact
An attacker can execute arbitrary code in the context of the affected application or user, giving full control of confidentiality, integrity and availability on the host. This can lead to complete system compromise without any prior privileges.
Attack surface
The vulnerability is network-reachable (AV:N) with no authentication required (Au:N), but exploitation requires some form of user interaction or a non-default condition (AC:M), such as viewing a crafted image or VML content. It is triggered through image parsing in Internet Explorer, Office, Visio, SQL Server Reporting Services and other products that use GDI+.
Exploitation
The record is not listed in CISA KEV and no ransomware groups are documented as using it, but EPSS is high at 0.529 (98.9th percentile), indicating a substantial probability of exploitation activity. Reference tags are limited to vendor and US Government advisories, with no public exploit tag supplied.
What to do
- Apply Microsoft security bulletin MS08-052 (the vendor patch for this GDI+ issue) to all affected products as the first action.
- Prioritize Internet Explorer, Office, Visio, SQL Server Reporting Services and Report Viewer installations, since these are the most exposed rendering paths.
- Block or restrict untrusted image and VML content at email and web gateways where feasible.
- Retire or isolate unsupported platforms such as Windows XP SP2/SP3 and Server 2003 SP1/SP2 that cannot receive current patches.
- Verify GdiPlus.dll and VGX.DLL versions against the MS08-052 fixed versions after patching.
Detection
- Monitor for crashes or heap corruption in processes loading GdiPlus.dll or VGX.DLL, especially iexplore.exe, winword.exe, excel.exe, visio.exe and Reporting Services processes.
- Hunt for suspicious image or VML files with abnormal gradient fill structures arriving via email or web download.
- Review endpoint logs for unexpected child processes spawned by Office, Internet Explorer or reporting services after opening image content.
- Check for the MS08-052 patch state on all hosts and flag any that still have the vulnerable GDI+ binaries.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
16 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-5348 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-5348), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.