Lucene search

K
cveMicrosoftCVE-2009-0221
HistoryMay 12, 2009 - 10:30 p.m.

CVE-2009-0221

2009-05-1222:30:00
CWE-189
microsoft
web.nvd.nist.gov
28
4
cve-2009-0221
microsoft
office
powerpoint
integer overflow
vulnerability
remote code execution
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.922

Percentile

99.0%

Integer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a PowerPoint file containing a crafted record type for โ€œcollaboration information for different slidesโ€ that contains a field that specifies a large number of records, which triggers an under-allocated buffer and a heap-based buffer overflow, aka โ€œInteger Overflow Vulnerability.โ€

Affected configurations

Nvd
Node
microsoftoffice_powerpointMatch2002sp3
OR
microsoftoffice_powerpointMatch2003sp3
VendorProductVersionCPE
microsoftoffice_powerpoint2002cpe:2.3:a:microsoft:office_powerpoint:2002:sp3:*:*:*:*:*:*
microsoftoffice_powerpoint2003cpe:2.3:a:microsoft:office_powerpoint:2003:sp3:*:*:*:*:*:*

Social References

More

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.922

Percentile

99.0%