PT-2009-4931 · Microsoft · Office Xp Sp3+1

CVE-2009-2528

·

Publicado

2009-10-14

·

Atualizado

2023-12-07

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Office XP SP3
Description The issue arises from the improper handling of malformed objects in Office Art Property Tables by GDI+ in Microsoft Office, allowing remote attackers to execute arbitrary code via a crafted Office document. This triggers memory corruption.
Recommendations For Microsoft Office XP SP3, update to a version that properly handles malformed objects in Office Art Property Tables to prevent memory corruption and arbitrary code execution.

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-2528

Produtos afetados

Gdi+
Office Xp Sp3