Integer overflow in GDI+ in Microsoft Office XP SP3 allows remote attackers to execute arbitrary code via an Office document with a bitmap (aka BMP) image that triggers memory corruption, aka "Office BMP Integer Overflow Vulnerability."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.556
EPSS Ranking 98.0%