CVE-2007-3034 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 51.9% (pctl 99)
Patch early
A public exploit exists.
Description
Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted metafile (image) with a large record length value, which triggers a heap-based buffer overflow.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 51.92% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-189 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-08-14 |
| Last modified | 2026-06-16 |
Affected (4)
| Vendor | Product |
|---|---|
| microsoft | windows 2000 |
| microsoft | windows 2003 server |
| microsoft | windows server 2003 |
| microsoft | windows xp |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Windows - 'gdi32.dll' Denial of Service (MS07-046) | 2007-08-29 |
References
- http://secunia.com/advisories/26423
- http://www.kb.cert.org/vuls/id/640136
- http://www.securityfocus.com/archive/1/476505/100/0/threaded
- http://www.securityfocus.com/bid/25302
- http://www.securitytracker.com/id?1018563
- http://www.us-cert.gov/cas/techalerts/TA07-226A.html
- http://www.vupen.com/english/advisories/2007/2870
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-046
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2088
- http://secunia.com/advisories/26423
- http://www.kb.cert.org/vuls/id/640136
- http://www.securityfocus.com/archive/1/476505/100/0/threaded
- http://www.securityfocus.com/bid/25302
- http://www.securitytracker.com/id?1018563
- http://www.us-cert.gov/cas/techalerts/TA07-226A.html
- http://www.vupen.com/english/advisories/2007/2870
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-046
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2088
→ the Explorer · watch your stack · NVD