Lucene search

K
cveMicrosoftCVE-2009-0097
HistoryFeb 10, 2009 - 10:30 p.m.

CVE-2009-0097

2009-02-1022:30:00
CWE-399
microsoft
web.nvd.nist.gov
66
cve-2009-0097
memory corruption
microsoft office
visio
remote code execution
security vulnerability

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.131

Percentile

95.6%

Microsoft Office Visio 2002 SP2 and 2003 SP3 does not properly validate memory allocation for Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka “Memory Corruption Vulnerability.”

Affected configurations

Nvd
Node
microsoftvisioMatch2002sp2
OR
microsoftvisioMatch2003sp3
OR
microsoftvisioMatch2007sp1
VendorProductVersionCPE
microsoftvisio2002cpe:2.3:a:microsoft:visio:2002:sp2:*:*:*:*:*:*
microsoftvisio2003cpe:2.3:a:microsoft:visio:2003:sp3:*:*:*:*:*:*
microsoftvisio2007cpe:2.3:a:microsoft:visio:2007:sp1:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.131

Percentile

95.6%