9.3

CVE-2009-2500

Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted WMF image file, aka "GDI+ WMF Integer Overflow Vulnerability."

Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows 2003 Server Updatesp2 Editionitanium
MicrosoftWindows 2003 Server Updatesp2 Editionx64
MicrosoftWindows Server 2008 Editionitanium
MicrosoftWindows Vista Editionx64
MicrosoftWindows Vista Updatesp1
MicrosoftWindows Xp Updatesp2
MicrosoftWindows Xp Updatesp2 Editionprofessional_x64
MicrosoftWindows Xp Updatesp3
Microsoft.Net Framework Version1.1 Updatesp1
   MicrosoftWindows 2000 Updatesp4
Microsoft.Net Framework Version2.0 Updatesp1
   MicrosoftWindows 2000 Updatesp4
Microsoft.Net Framework Version2.0 Updatesp2
   MicrosoftWindows 2000 Updatesp4
MicrosoftInternet Explorer Version6 Updatesp1
   MicrosoftWindows 2000 Updatesp4
MicrosoftReport Viewer Version2005 Updatesp1 Editionredistributable_package
MicrosoftReport Viewer Version2008 Editionredistributable_package
MicrosoftReport Viewer Version2008 Updatesp1 Editionredistributable_package
MicrosoftSql Server Version2005 Updatesp2
MicrosoftSql Server Version2005 Updatesp2 Editionitanium
MicrosoftSql Server Version2005 Updatesp2 Editionx64
MicrosoftSql Server Version2005 Updatesp3
MicrosoftSql Server Version2005 Updatesp3 Editionitanium
MicrosoftSql Server Version2005 Updatesp3 Editionx64
MicrosoftSql Server Reporting Services Version2000 Updatesp2
MicrosoftExcel Viewer Version2003
MicrosoftExcel Viewer Version2003 Updatesp3
MicrosoftExpression Web Version2
MicrosoftOffice Version2003 Updatesp3
MicrosoftOffice Version2007 Updatesp1
MicrosoftOffice Version2007 Updatesp2
MicrosoftOffice Versionxp
MicrosoftOffice Compatibility Pack Version2007 Updatesp1
MicrosoftOffice Compatibility Pack Version2007 Updatesp2
MicrosoftOffice Groove Version2007
MicrosoftOffice Groove Version2007 Updatesp1
MicrosoftOffice Powerpoint Viewer Version2007 Updatesp1
MicrosoftOffice Powerpoint Viewer Version2007 Updatesp2
MicrosoftProject Version2002 Updatesp1
MicrosoftVisio Version2002 Updatesp2
MicrosoftWord Viewer Version2003
MicrosoftWord Viewer Version2003 Updatesp3
MicrosoftWorks Version8.5
MicrosoftReport Viewer Version2005 Updatesp1 Editionredistributable_package
MicrosoftReport Viewer Version2008 Editionredistributable_package
MicrosoftReport Viewer Version2008 Updatesp1 Editionredistributable_package
MicrosoftVisual Studio Version2008
MicrosoftVisual Studio Version2008 Updatesp1
MicrosoftVisual Studio .Net Version2003 Updatesp1
MicrosoftVisual Studio .Net Version2005 Updatesp1
MicrosoftForefront Client Security Version1.0
   MicrosoftWindows 2000 Updatesp4
MicrosoftVisual Foxpro Version8.0 Updatesp1
   MicrosoftWindows 2000 Updatesp4
MicrosoftVisual Foxpro Version9.0 Updatesp2
   MicrosoftWindows 2000 Updatesp4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 56.77% 0.981
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C