Vulnerabilities > CVE-2007-2237 - Divide By Zero vulnerability in Microsoft Windows XP

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
local
low complexity
microsoft
CWE-369
exploit available

Summary

Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error.

Vulnerable Configurations

Part Description Count
OS
Microsoft
1

Common Weakness Enumeration (CWE)

Exploit-Db

  • descriptionMicrosoft Windows XP GDI+ ICO File Remote Denial of Service Vulnerability. CVE-2007-2237. Dos exploit for windows platform
    idEDB-ID:30160
    last seen2016-02-03
    modified2007-06-06
    published2007-06-06
    reporterDennis Rand
    sourcehttps://www.exploit-db.com/download/30160/
    titleMicrosoft Windows XP - GDI+ ICO File Remote Denial of Service Vulnerability
  • idEDB-ID:4044

Seebug

  • bulletinFamilyexploit
    descriptionNo description provided by source.
    idSSV:6915
    last seen2017-11-19
    modified2007-06-08
    published2007-06-08
    reporterRoot
    sourcehttps://www.seebug.org/vuldb/ssvid-6915
    titleMS Windows GDI+ ICO File Remote Denial of Service Exploit
  • bulletinFamilyexploit
    descriptionNo description provided by source.
    idSSV:64746
    last seen2017-11-19
    modified2014-07-01
    published2014-07-01
    reporterRoot
    sourcehttps://www.seebug.org/vuldb/ssvid-64746
    titleMS Windows GDI+ ICO File - Remote Denial of Service Exploit