Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-025
No PoCs found on GitHub currently.