CVE-2009-2528
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD
Description
GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vulnerability."
Affected (56)
Products: Microsoft: Windows 2003 Server, Windows Server 2008, Windows Vista, Windows Xp, .net Framework, Internet Explorer, Sql Server, Sql Server Reporting Services, Excel Viewer, Expression Web, Office, Office Compatibility Pack, Office Excel Viewer, Office Groove, Office Powerpoint Viewer, Office Word Viewer, Project, Visio, Word Viewer, Works, Platform Sdk, Report Viewer, Visual Studio, Visual Studio .net, Forefront Client Security, Visual Foxpro
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions | |
| All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.1 sp1 | |
| Version 6 sp1 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2005 sp2 | |
| Version 2000 sp2 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2003 | |
| All versions | |
| Version 2003 sp3 | |
| Version 2007 sp1 | |
| All versions | |
| Version 2007 | |
| All versions | |
| All versions | |
| Version 2002 sp1 | |
| Version 2002 sp2 | |
| Version 2003 | |
| Version 8.5 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| Version 2005 sp1 | |
| Version 2008 | |
| Version 2003 sp1 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0 | |
| Version 8.0 sp1 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 2000 | All versions |
References (6)
Source: secure@microsoft.com
US Government Resource
Source: secure@microsoft.com
Source: secure@microsoft.com
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.