peter bassill · operator
$ cve CVE-2008-3465 JSON

CVE-2008-3465

9.8
CRITICAL · CVSS 3.1 · EPSS 13.7% (pctl 96)

Patch early

EPSS 13.7% — above the 10% action threshold.

Description

Heap-based buffer overflow in an API in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows context-dependent attackers to cause a denial of service or execute arbitrary code via a WMF file with a malformed file-size parameter, which would not be properly handled by a third-party application that uses this API for a copy operation, aka "GDI Heap Overflow Vulnerability."

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS13.67% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploitnone known
Published2008-12-10
Last modified2026-06-16

Affected (6)

VendorProduct
microsoftwindows 2000
microsoftwindows 2003 server
microsoftwindows server 2003
microsoftwindows server 2008
microsoftwindows vista
microsoftwindows xp

References

→ the Explorer  ·  watch your stack  ·  NVD