← Back

CVE-2009-0102

nvd nist
Published: Dec 9, 2009Modified: Apr 23, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka "Project Memory Validation Vulnerability."

Affected (7)

3 products
Office Project
Project Portfolio Server
Project Server
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 2007 sp1
Version 2007 sp2
Microsoft
Version 2007 sp1
Version 2007 sp2
Microsoft
Version 2003 sp3
Version 2007 sp1
Version 2007 sp2

Related CWEs

Timeline

No history available yet.