Vulnerability CVE-2009-2518


Published: 2009-10-14   Modified: 2012-02-13

Description:
Integer overflow in GDI+ in Microsoft Office XP SP3 allows remote attackers to execute arbitrary code via an Office document with a bitmap (aka BMP) image that triggers memory corruption, aka "Office BMP Integer Overflow Vulnerability."

Type:

CWE-189

(Numeric Errors)

Vendor: Microsoft
Product: Office 
Version: xp; 2003;
Product: Office xp 
Version: sp3;
Product: 20007 office system 
Version: sp2; sp1;
Product: Works 
Version: 8.5;
Product: Internet explorer 
Version: 6;
Product: Report viewer 
Version: 2008; 2005;
Product: Office powerpoint 
Version: 2007;
Product: Office groove 
Version: 2007;
Product: Sql server 
Version: 2005;
Product: Office word viewer 
Version: 2003;
Product: Office excel viewer 
Version: 2003;
Product: Office project 
Version: 2002;
Product: Office visio 
Version: 2002;
Product: .net framework 
Version: 2.0; 1.1;
Product: Forefront client security 
Version: 1.0;
Product: Windows server 2008 
Product: Windows 2003 server 
Product: Windows vista 
Product: Office compatibility pack for word excel ppt 2007 
Product: Windows xp 
Product: Windows 2000 

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.3/10
10/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete

 References:
http://www.us-cert.gov/cas/techalerts/TA09-286A.html
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-062
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6430

Related CVE
CVE-2019-0879
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0846, CVE-2019-0847, CVE-2019-0...
CVE-2019-0877
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0846, CVE-2019-0847, CVE-2019-0...
CVE-2019-0876
An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'.
CVE-2019-0875
An elevation of privilege vulnerability exists when Azure DevOps Server 2019 does not properly enforce project permissions, aka 'Azure DevOps Server Elevation of Privilege Vulnerability'.
CVE-2019-0874
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'.
CVE-2019-0871
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID i...
CVE-2019-0870
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID i...
CVE-2019-0869
A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'.

Copyright 2019, cxsecurity.com

 

Back to Top