Lucene search

K
cve[email protected]CVE-2009-1132
HistorySep 08, 2009 - 10:30 p.m.

CVE-2009-1132

2009-09-0822:30:00
CWE-119
web.nvd.nist.gov
21
cve-2009-1132
wlansvc
buffer overflow
windows
wireless frame parsing
remote code execution
vulnerability
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.5 High

AI Score

Confidence

Low

0.524 Medium

EPSS

Percentile

97.6%

Heap-based buffer overflow in the Wireless LAN AutoConfig Service (aka Wlansvc) in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed wireless frame, aka “Wireless Frame Parsing Remote Code Execution Vulnerability.”

Affected configurations

NVD
Node
microsoftwindows_server_2008Match--x32
OR
microsoftwindows_server_2008Match--x64
OR
microsoftwindows_server_2008Match-sp2x64
OR
microsoftwindows_server_2008Match-sp2x86
OR
microsoftwindows_vista
OR
microsoftwindows_vistasp1
OR
microsoftwindows_vistasp2
OR
microsoftwindows_vistaMatch--x64
OR
microsoftwindows_vistaMatch-sp1
OR
microsoftwindows_vistaMatch-sp2

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.5 High

AI Score

Confidence

Low

0.524 Medium

EPSS

Percentile

97.6%