CVE-2009-2499

Microsoft Windows Media Format Runtime 9.0, 9.5, and 11; and Microsoft Media Foundation on Windows Vista Gold, SP1, and SP2 and Server 2008; allows remote attackers to execute arbitrary code via an MP3 file with crafted metadata that triggers memory corruption, aka "Windows Media Playback Memory Corruption Vulnerability."
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.5 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:C/I:C/A:C
microsoftCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
VendorProductVersion
microsoftwindows_media_format_runtime
9.0
microsoftwindows_2000
-
microsoftwindows_xp
-
microsoftwindows_xp
-
microsoftwindows_media_format_runtime
9.5
microsoftwindows_server_2003
*
microsoftwindows_xp
*
microsoftwindows_xp
-
microsoftwindows_xp
-
microsoftwindows_media_format_runtime
9.5
microsoftwindows_server_2003
*
microsoftwindows_xp
*
microsoftwindows_server_2008
-
microsoftwindows_server_2008
-
microsoftwindows_server_2008
-
microsoftwindows_server_2008
-
microsoftwindows_vista
*
microsoftwindows_vista
*
microsoftwindows_vista
*
microsoftwindows_vista
*
microsoftwindows_vista
-
microsoftwindows_vista
-
microsoftwindows_xp
*
microsoftwindows_xp
-
microsoftwindows_xp
-
microsoftwindows_media_services
9.1
microsoftwindows_server_2003
*
microsoftwindows_server_2003
*
microsoftwindows_server_2008
-
microsoftwindows_server_2008
-
microsoftwindows_server_2008
-
microsoftwindows_server_2008
-
microsoftwindows_media_foundation
-
microsoftwindows_server_2008
-
microsoftwindows_server_2008
-
microsoftwindows_server_2008
-
microsoftwindows_server_2008
-
microsoftwindows_vista
*
microsoftwindows_vista
*
microsoftwindows_vista
*
microsoftwindows_vista
-
microsoftwindows_vista
-
microsoftwindows_vista
-
𝑥
= Vulnerable software versions