PT-2009-4931 · Microsoft · Office Xp Sp3+1
CVE-2009-2528
·
Publicado
2009-10-14
·
Atualizado
2023-12-07
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Office XP SP3
Description
The issue arises from the improper handling of malformed objects in Office Art Property Tables by GDI+ in Microsoft Office, allowing remote attackers to execute arbitrary code via a crafted Office document. This triggers memory corruption.
Recommendations
For Microsoft Office XP SP3, update to a version that properly handles malformed objects in Office Art Property Tables to prevent memory corruption and arbitrary code execution.
Correção
RCE
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Gdi+
Office Xp Sp3