← back
CVE-2004-1049observed exploitation

CVE-2004-1049

37Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendepss 31%
from disclosure to weapon
Published on NVDJan 19
VulnCheck+1928d
exploitation probability
31%top 2% of all CVEs
observed exploitation
yesVulnCheck
Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon Format Handling Vulnerability."
Affected products
n/a · n/a