Vulnerability record · CVE-2010-0028 · published 10 February 2010
CVE-2010-0028: Microsoft Paint integer overflow allows code execution via crafted JPEG
Microsoft · Windows 2000
Microsoft Paint on Windows 2000 SP4, XP SP2/SP3 and Server 2003 SP2 contains an integer overflow that is triggered when parsing a crafted JPEG (.JPG) file. Successful exploitation lets a remote attacker run arbitrary code in the context of the user who opens the file. The affected platforms are long out of support, so exposure is limited to legacy systems still running them.
Description
Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted JPEG (.JPG) file, aka "MS Paint Integer Overflow Vulnerability."
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with complete confidentiality, integrity and availability impact and a high EPSS score, but limited to unsupported legacy Windows versions and requiring user interaction.
What it is
Microsoft Paint on Windows 2000 SP4, XP SP2/SP3 and Server 2003 SP2 contains an integer overflow that is triggered when parsing a crafted JPEG (.JPG) file. Successful exploitation lets a remote attacker run arbitrary code in the context of the user who opens the file. The affected platforms are long out of support, so exposure is limited to legacy systems still running them.
Impact
An attacker gains arbitrary code execution with the privileges of the user who opens the malicious JPEG, which can lead to full compromise of the workstation.
Attack surface
The flaw is reached remotely by delivering a crafted JPEG that the victim opens in Microsoft Paint; no authentication is required, but user interaction (opening the file) is needed, consistent with the AV:N/AC:M/Au:N vector.
Exploitation
Not listed in CISA KEV and no reference is tagged as exploit code, though EPSS is high (0.48452, 98.8th percentile), indicating elevated predicted likelihood of exploitation activity.
What to do
- Apply Microsoft security bulletin MS10-005 for the affected Windows versions where still deployed.
- Retire or isolate Windows 2000, XP and Server 2003 systems that cannot be patched.
- Block or inspect untrusted JPEG attachments and downloads at email and web gateways.
- Avoid opening JPEG files from untrusted sources in Microsoft Paint; use a hardened, updated image viewer instead.
Detection
- Monitor for Microsoft Paint (mspaint.exe) spawning child processes such as cmd.exe or script hosts.
- Alert on unexpected process creation or network connections originating from mspaint.exe.
- Hunt for JPEG files delivered via email or web downloads that are subsequently opened by mspaint.exe on legacy hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-0028 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-0028), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.