CVE-2009-2528

Published Oct 14, 2009

Last updated 4 days ago

Overview

Description
GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vulnerability."
Source
secure@microsoft.com
NVD status
Modified
Products
windows_2003_server, windows_server_2008, windows_vista, windows_xp, .net_framework, internet_explorer, report_viewer, sql_server, sql_server_reporting_services, excel_viewer, expression_web, office, office_compatibility_pack, office_excel_viewer, office_groove, office_powerpoint_viewer, office_word_viewer, project, visio, word_viewer, works, platform_sdk, visual_studio, visual_studio_.net, forefront_client_security, visual_foxpro

Risk scores

CVSS 2.0

Type
Primary
Base score
9.3
Impact score
10
Exploitability score
8.6
Vector string
AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

nvd@nist.gov
CWE-94

Social media

Hype score
Not currently trending

Configurations