Off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP allows remote attackers to cause a denial of service (stack corruption and application termination) via a crafted EMF file that triggers an integer overflow, as demonstrated by voltage-exploit.emf, aka the "Microsoft GdiPlus EMF GpFont.SetData integer overflow."
Conclusion & alert: CVE-2009-1217 is rated High Exploit Risk (71.5/100): CVSS Medium severity, with high exploitation likelihood (EPSS 56.39%, 98th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +6.35% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 8281 | exploit_db | edb | 2009-03-24 | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-02-08 | 50.04% | 56.39% | +6.35% |
| 2 | 2025-12-28 | 46.23% | 50.04% | +3.81% |
| 3 | 2025-12-27 | — | 46.23% | — |
Full EPSS history (20 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
| URL | Tags |
|---|---|
| http://bl4cksecurity.blogspot.com/2009/03/microsoft-gdiplus-emf-gpfontsetdata.html | Broken Link |
| http://blogs.technet.com/srd/archive/2009/03/26/new-emf-gdiplus-dll-crash-not-exploitable-for-code-execution.aspx | Broken Link |
| http://www.securityfocus.com/bid/34250 | Third Party Advisory VDB Entry |
| http://www.vupen.com/english/advisories/2009/0832 | Vendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/49438 | Third Party Advisory VDB Entry |