Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-2528

Опубликовано: 14 окт. 2009
Источник: nvd
CVSS2: 9.3
EPSS Средний

Описание

GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vulnerability."

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:*:sp2:itanium:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:*:sp2:x64:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2008:*:*:itanium:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2008:*:*:x32:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2008:*:*:x64:*:*:*:*:*
cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_vista:*:*:x64:*:*:*:*:*
cpe:2.3:o:microsoft:windows_vista:*:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp2:professional_x64:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp3:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*

Одно из

cpe:2.3:a:microsoft:.net_framework:1.1:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net_framework:2.0:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net_framework:2.0:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:6:sp1:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:a:microsoft:report_viewer:2005:sp1:redistributable_package:*:*:*:*:*
cpe:2.3:a:microsoft:report_viewer:2008:*:redistributable_package:*:*:*:*:*
cpe:2.3:a:microsoft:report_viewer:2008:sp1:redistributable_package:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:2005:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:2005:sp2:itanium:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:2005:sp2:x64:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:2005:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:2005:sp3:itanium:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:2005:sp3:x64:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server_reporting_services:2000:sp2:*:*:*:*:*:*
Конфигурация 4

Одно из

cpe:2.3:a:microsoft:excel_viewer:2003:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:excel_viewer:2003:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:expression_web:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:expression_web:2:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:2007:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:2007:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:xp:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_compatibility_pack:2007:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_compatibility_pack:2007:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_excel_viewer:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_groove:2007:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_groove:2007:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_powerpoint_viewer:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_powerpoint_viewer:2007:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_powerpoint_viewer:2007:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_word_viewer:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:project:2002:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:visio:2002:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:word_viewer:2003:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:word_viewer:2003:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:works:8.5:*:*:*:*:*:*:*
Конфигурация 5

Одно из

cpe:2.3:a:microsoft:platform_sdk:*:*:redistrutable_gdi\+:*:*:*:*:*
cpe:2.3:a:microsoft:report_viewer:2005:sp1:redistributable_package:*:*:*:*:*
cpe:2.3:a:microsoft:report_viewer:2008:*:redistributable_package:*:*:*:*:*
cpe:2.3:a:microsoft:report_viewer:2008:sp1:redistributable_package:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio:2008:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio:2008:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_.net:2003:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_.net:2005:sp1:*:*:*:*:*:*
Конфигурация 6

Одновременно

Одно из

cpe:2.3:a:microsoft:forefront_client_security:1.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_foxpro:8.0:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_foxpro:9.0:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*

EPSS

Процентиль: 97%
0.41196
Средний

9.3 Critical

CVSS2

Дефекты

CWE-94

Связанные уязвимости

github
почти 4 года назад

GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vulnerability."

EPSS

Процентиль: 97%
0.41196
Средний

9.3 Critical

CVSS2

Дефекты

CWE-94