← Vulnerability feed

Vulnerability record · CVE-2010-0028 · published 10 February 2010

CVE-2010-0028: Microsoft Paint integer overflow allows code execution via crafted JPEG

Microsoft · Windows 2000

Microsoft Paint on Windows 2000 SP4, XP SP2/SP3 and Server 2003 SP2 contains an integer overflow that is triggered when parsing a crafted JPEG (.JPG) file. Successful exploitation lets a remote attacker run arbitrary code in the context of the user who opens the file. The affected platforms are long out of support, so exposure is limited to legacy systems still running them.

9.3 CVSS 2.0 High EPSS 48% · top 1.2% CWE-189 · CWE-189
9.3CVSS 2.0 base score
48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted JPEG (.JPG) file, aka "MS Paint Integer Overflow Vulnerability."

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote code execution with complete confidentiality, integrity and availability impact and a high EPSS score, but limited to unsupported legacy Windows versions and requiring user interaction.

What it is

Microsoft Paint on Windows 2000 SP4, XP SP2/SP3 and Server 2003 SP2 contains an integer overflow that is triggered when parsing a crafted JPEG (.JPG) file. Successful exploitation lets a remote attacker run arbitrary code in the context of the user who opens the file. The affected platforms are long out of support, so exposure is limited to legacy systems still running them.

Impact

An attacker gains arbitrary code execution with the privileges of the user who opens the malicious JPEG, which can lead to full compromise of the workstation.

Attack surface

The flaw is reached remotely by delivering a crafted JPEG that the victim opens in Microsoft Paint; no authentication is required, but user interaction (opening the file) is needed, consistent with the AV:N/AC:M/Au:N vector.

Exploitation

Not listed in CISA KEV and no reference is tagged as exploit code, though EPSS is high (0.48452, 98.8th percentile), indicating elevated predicted likelihood of exploitation activity.

What to do

  • Apply Microsoft security bulletin MS10-005 for the affected Windows versions where still deployed.
  • Retire or isolate Windows 2000, XP and Server 2003 systems that cannot be patched.
  • Block or inspect untrusted JPEG attachments and downloads at email and web gateways.
  • Avoid opening JPEG files from untrusted sources in Microsoft Paint; use a hardened, updated image viewer instead.

Detection

  • Monitor for Microsoft Paint (mspaint.exe) spawning child processes such as cmd.exe or script hosts.
  • Alert on unexpected process creation or network connections originating from mspaint.exe.
  • Hunt for JPEG files delivered via email or web downloads that are subsequently opened by mspaint.exe on legacy hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-0028 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2015-2360Microsoft Windows win32k.sys memory corruption privilege escalationwin32k.sys in the Windows kernel-mode drivers mishandles memory, allowing a local user to corrupt memory through a crafted application. The flaw is a…KEVEPSS 15%analysed8.8CVE-2014-6324Microsoft Windows Kerberos KDC privilege escalation via forged ticket signatureThe Kerberos Key Distribution Center (KDC) in multiple Windows client and server versions fails to properly validate the signature (checksum) in a ti…KEVEPSS 87%analysed8.8CVE-2014-6332Windows OLE Automation SafeArrayDimen array redimensioning remote code executionOleAut32.dll in Windows OLE mishandles a size value in the SafeArrayDimen function, allowing an array-redimensioning attempt to corrupt memory. A cra…KEVEPSS 95%analysed8.8CVE-2014-4148Windows win32k.sys TrueType font parsing remote code executionA code injection flaw in the win32k.sys kernel-mode driver lets a crafted TrueType font trigger arbitrary code execution. Because font parsing sits i…KEVEPSS 60%analysed8.8CVE-2013-3918Microsoft Windows InformationCardSigninHelper ActiveX out-of-bounds writeThe InformationCardSigninHelper ActiveX control in icardie.dll contains an out-of-bounds write that can be triggered by a crafted web page rendered i…KEVEPSS 74%analysed8.8CVE-2011-3402Microsoft Windows TrueType Font Parsing Remote Code ExecutionThe TrueType font parsing engine in win32k.sys on multiple Windows versions fails to properly handle crafted font data, allowing remote code executio…KEVEPSS 78%analysed8.8CVE-2008-0015Microsoft DirectShow Video ActiveX Control Stack Buffer OverflowA stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequ…KEVEPSS 77%analysed

Source: NIST National Vulnerability Database (record CVE-2010-0028), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.