9.3
CVE-2009-2528
- EPSS 41.2%
- Veröffentlicht 14.10.2009 10:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle secure@microsoft.com
- Teams Watchlist Login
- Unerledigt Login
GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2003 Server Updatesp2
Microsoft ≫ Windows 2003 Server Updatesp2 Editionitanium
Microsoft ≫ Windows 2003 Server Updatesp2 Editionx64
Microsoft ≫ Windows Server 2008 Editionitanium
Microsoft ≫ Windows Server 2008 Editionx32
Microsoft ≫ Windows Server 2008 Editionx64
Microsoft ≫ Windows Vista Editionx64
Microsoft ≫ Windows Vista Updatesp1
Microsoft ≫ Windows Xp Updatesp2
Microsoft ≫ Windows Xp Updatesp2 Editionprofessional_x64
Microsoft ≫ Windows Xp Updatesp3
Microsoft ≫ .Net Framework Version1.1 Updatesp1
Microsoft ≫ .Net Framework Version2.0 Updatesp1
Microsoft ≫ .Net Framework Version2.0 Updatesp2
Microsoft ≫ Internet Explorer Version6 Updatesp1
Microsoft ≫ Report Viewer Version2005 Updatesp1 Editionredistributable_package
Microsoft ≫ Report Viewer Version2008 Editionredistributable_package
Microsoft ≫ Report Viewer Version2008 Updatesp1 Editionredistributable_package
Microsoft ≫ Sql Server Version2005 Updatesp2
Microsoft ≫ Sql Server Version2005 Updatesp2 Editionitanium
Microsoft ≫ Sql Server Version2005 Updatesp2 Editionx64
Microsoft ≫ Sql Server Version2005 Updatesp3
Microsoft ≫ Sql Server Version2005 Updatesp3 Editionitanium
Microsoft ≫ Sql Server Version2005 Updatesp3 Editionx64
Microsoft ≫ Sql Server Reporting Services Version2000 Updatesp2
Microsoft ≫ Excel Viewer Version2003
Microsoft ≫ Excel Viewer Version2003 Updatesp3
Microsoft ≫ Expression Web Version2
Microsoft ≫ Office Compatibility Pack Version2007 Updatesp1
Microsoft ≫ Office Compatibility Pack Version2007 Updatesp2
Microsoft ≫ Office Groove Version2007
Microsoft ≫ Office Groove Version2007 Updatesp1
Microsoft ≫ Office Powerpoint Viewer Version2007 Updatesp1
Microsoft ≫ Office Powerpoint Viewer Version2007 Updatesp2
Microsoft ≫ Word Viewer Version2003
Microsoft ≫ Word Viewer Version2003 Updatesp3
Microsoft ≫ Report Viewer Version2005 Updatesp1 Editionredistributable_package
Microsoft ≫ Report Viewer Version2008 Editionredistributable_package
Microsoft ≫ Report Viewer Version2008 Updatesp1 Editionredistributable_package
Microsoft ≫ Visual Studio Version2008
Microsoft ≫ Visual Studio Version2008 Updatesp1
Microsoft ≫ Visual Studio .Net Version2003 Updatesp1
Microsoft ≫ Visual Studio .Net Version2005 Updatesp1
Microsoft ≫ Forefront Client Security Version1.0
Microsoft ≫ Visual Foxpro Version8.0 Updatesp1
Microsoft ≫ Visual Foxpro Version9.0 Updatesp2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 41.2% | 0.973 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-94 Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.