Vulnerability CVE-2009-2518


Published: 2009-10-14   Modified: 2012-02-13

Description:
Integer overflow in GDI+ in Microsoft Office XP SP3 allows remote attackers to execute arbitrary code via an Office document with a bitmap (aka BMP) image that triggers memory corruption, aka "Office BMP Integer Overflow Vulnerability."

Vendor: Microsoft
Product: Office 
Version: xp; 2003;
Product: Office xp 
Version: sp3;
Product: 20007 office system 
Version: sp2; sp1;
Product: Works 
Version: 8.5;
Product: Internet explorer 
Version: 6;
Product: Report viewer 
Version: 2008; 2005;
Product: Office powerpoint 
Version: 2007;
Product: Office groove 
Version: 2007;
Product: Sql server 
Version: 2005;
Product: Office word viewer 
Version: 2003;
Product: Office excel viewer 
Version: 2003;
Product: Office project 
Version: 2002;
Product: Office visio 
Version: 2002;
Product: .net framework 
Version: 2.0; 1.1;
Product: Forefront client security 
Version: 1.0;
Product: Windows server 2008 
Product: Windows 2003 server 
Product: Windows vista 
Product: Office compatibility pack for word excel ppt 2007 
Product: Windows xp 
Product: Windows 2000 

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.3/10
10/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete

 References:
http://www.microsoft.com/technet/security/Bulletin/MS09-062.mspx
http://www.us-cert.gov/cas/techalerts/TA09-286A.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6430

Related CVE
CVE-2018-8404
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows Server 2012, Wi...
CVE-2018-8398
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Win...
CVE-2018-8394
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Win...
CVE-2018-8349
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Wind...
CVE-2018-8348
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 200...
CVE-2018-8345
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed, aka "LNK Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windo...
CVE-2018-8344
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8...
CVE-2018-8343
An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it, aka "Windows NDIS Elevation of Privilege Vulnerability." This affec...

Copyright 2018, cxsecurity.com

 

Back to Top