Tracker / CVE-2009-2528
CVE-2009-2528
High 9.3
GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vulnerability."
Affected products and versions
| microsoft | .net_framework |
|---|---|
| microsoft | excel_viewer |
| microsoft | expression_web |
| microsoft | forefront_client_security |
| microsoft | internet_explorer |
| microsoft | office |
| microsoft | office_compatibility_pack |
| microsoft | office_excel_viewer |
| microsoft | office_groove |
| microsoft | office_powerpoint_viewer |
| microsoft | office_word_viewer |
| microsoft | platform_sdk |
| microsoft | project |
| microsoft | report_viewer |
| microsoft | sql_server |
| microsoft | sql_server_reporting_services |
| microsoft | visio |
| microsoft | visual_foxpro |
| microsoft | visual_studio |
| microsoft | visual_studio_.net |
| microsoft | windows_2003_server |
| microsoft | windows_server_2008 |
| microsoft | windows_vista |
| microsoft | windows_xp |
| microsoft | word_viewer |
| microsoft | works |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.