CVE-2009-2528

GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vulnerability."
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
microsoftCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
VendorProductVersion
microsoftwindows_2003_server
*
microsoftwindows_2003_server
*
microsoftwindows_2003_server
*
microsoftwindows_server_2008
*
microsoftwindows_server_2008
*
microsoftwindows_server_2008
*
microsoftwindows_vista
*
microsoftwindows_vista
*
microsoftwindows_vista
*
microsoftwindows_xp
*
microsoftwindows_xp
*
microsoftwindows_xp
*
microsoft.net_framework
1.1:sp1
microsoft.net_framework
2.0:sp1
microsoft.net_framework
2.0:sp2
microsoftexpression_web
*
microsoftoffice_excel_viewer
*
microsoftoffice_powerpoint_viewer
*
microsoftoffice_word_viewer
*
microsoftworks
8.5
microsoftplatform_sdk
*
microsoftforefront_client_security
1.0
microsoftvisual_foxpro
8.0:sp1
microsoftvisual_foxpro
9.0:sp2
𝑥
= Vulnerable software versions