← Vulnerability feed

Vulnerability record · CVE-2007-5348 · published 11 September 2008

CVE-2007-5348: Microsoft GDI+ gradient fill integer overflow leads to remote code execution

Microsoft · Digital Image Suite

GDI+ in a wide range of Microsoft products mishandles crafted gradient sizes in gradient fill input, causing an integer overflow that leads to a heap-based buffer overflow in GdiPlus.dll and VGX.DLL. Because the affected component is reachable through image and VML rendering, a malicious file or web page can corrupt memory and run attacker-controlled code. The flaw is known as the GDI+ VML Buffer Overrun Vulnerability.

9.3 CVSS 2.0 High EPSS 53% · top 1.1% CWE-189 · CWE-189
9.3CVSS 2.0 base score
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
16Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via an image file with crafted gradient sizes in gradient fill input, which triggers a heap-based buffer overflow related to GdiPlus.dll and VGX.DLL, aka "GDI+ VML Buffer Overrun Vulnerability."

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityCVSS 9.3 and a 98.9th percentile EPSS score indicate severe, remotely reachable code execution with a high likelihood of attempted exploitation, though it is not in KEV and requires some user interaction.

What it is

GDI+ in a wide range of Microsoft products mishandles crafted gradient sizes in gradient fill input, causing an integer overflow that leads to a heap-based buffer overflow in GdiPlus.dll and VGX.DLL. Because the affected component is reachable through image and VML rendering, a malicious file or web page can corrupt memory and run attacker-controlled code. The flaw is known as the GDI+ VML Buffer Overrun Vulnerability.

Impact

An attacker can execute arbitrary code in the context of the affected application or user, giving full control of confidentiality, integrity and availability on the host. This can lead to complete system compromise without any prior privileges.

Attack surface

The vulnerability is network-reachable (AV:N) with no authentication required (Au:N), but exploitation requires some form of user interaction or a non-default condition (AC:M), such as viewing a crafted image or VML content. It is triggered through image parsing in Internet Explorer, Office, Visio, SQL Server Reporting Services and other products that use GDI+.

Exploitation

The record is not listed in CISA KEV and no ransomware groups are documented as using it, but EPSS is high at 0.529 (98.9th percentile), indicating a substantial probability of exploitation activity. Reference tags are limited to vendor and US Government advisories, with no public exploit tag supplied.

What to do

  • Apply Microsoft security bulletin MS08-052 (the vendor patch for this GDI+ issue) to all affected products as the first action.
  • Prioritize Internet Explorer, Office, Visio, SQL Server Reporting Services and Report Viewer installations, since these are the most exposed rendering paths.
  • Block or restrict untrusted image and VML content at email and web gateways where feasible.
  • Retire or isolate unsupported platforms such as Windows XP SP2/SP3 and Server 2003 SP1/SP2 that cannot receive current patches.
  • Verify GdiPlus.dll and VGX.DLL versions against the MS08-052 fixed versions after patching.

Detection

  • Monitor for crashes or heap corruption in processes loading GdiPlus.dll or VGX.DLL, especially iexplore.exe, winword.exe, excel.exe, visio.exe and Reporting Services processes.
  • Hunt for suspicious image or VML files with abnormal gradient fill structures arriving via email or web download.
  • Review endpoint logs for unexpected child processes spawned by Office, Internet Explorer or reporting services after opening image content.
  • Check for the MS08-052 patch state on all hosts and flag any that still have the vulnerable GDI+ binaries.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

16 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-5348 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed9.8CVE-2015-0313Adobe Flash Player use-after-free allows remote code executionAdobe Flash Player contains a use-after-free (CWE-416) flaw reachable through unspecified vectors. It affects Flash Player before 13.0.0.269 and 14.x…KEVEPSS 95%analysed9.8CVE-2015-0311Adobe Flash Player unspecified flaw allows remote code executionCVE-2015-0311 is an unspecified vulnerability in Adobe Flash Player affecting versions through 13.0.0.262, 14.x, 15.x, and 16.x through 16.0.0.287 on…KEVEPSS 86%analysed9.8CVE-2014-1776Internet Explorer use-after-free in CMarkup::IsConnectedToPrimaryMarkupMicrosoft Internet Explorer 6 through 11 contains a use-after-free in the CMarkup::IsConnectedToPrimaryMarkup function that allows remote code execut…KEVEPSS 83%analysed8.8CVE-2023-35311Microsoft Outlook security feature bypass via TOCTOU race conditionCVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects …KEVEPSS 16%analysed8.8CVE-2021-27085Microsoft Internet Explorer remote code execution flawCVE-2021-27085 is a remote code execution vulnerability in Microsoft Internet Explorer. The record gives only a one-line description and no root-caus…KEVEPSS 5.4%analysed8.8CVE-2021-26411Microsoft Internet Explorer and Edge use-after-free memory corruptionCVE-2021-26411 is a use-after-free (CWE-416) memory corruption flaw in Microsoft Internet Explorer, with Microsoft Edge also listed as an affected pr…KEVEPSS 81%analysed8.8CVE-2019-1297Microsoft Excel memory handling flaw allows remote code executionCVE-2019-1297 is a remote code execution vulnerability in Microsoft Excel caused by improper handling of objects in memory. An attacker who convinces…KEVEPSS 22%analysed

Source: NIST National Vulnerability Database (record CVE-2007-5348), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.