Lucene search

K
cveMicrosoftCVE-2009-2506
HistoryDec 09, 2009 - 6:30 p.m.

CVE-2009-2506

2009-12-0918:30:00
CWE-189
microsoft
web.nvd.nist.gov
43
cve-2009-2506
integer overflow
microsoft office
word
works
office converter pack
wordpad
windows 2000
xp
server 2003
remote code execution
buffer overflow

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.941

Percentile

99.2%

Integer overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3; Works 8.5; Office Converter Pack; and WordPad in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a DOC file with an invalid number of property names in the DocumentSummaryInformation stream, which triggers a heap-based buffer overflow.

Affected configurations

Nvd
Node
microsoftwindows_2000sp4
OR
microsoftwindows_server_2003sp2
OR
microsoftwindows_xpsp2
OR
microsoftwindows_xpsp2x64
OR
microsoftwindows_xpsp3
AND
microsoftoffice_converter_pack
OR
microsoftoffice_wordMatch2002sp3
OR
microsoftoffice_wordMatch2003sp3
OR
microsoftwordpad
OR
microsoftworksMatch8.5
VendorProductVersionCPE
microsoftwindows_2000*cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*
microsoftwindows_server_2003*cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*
microsoftwindows_xp*cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*
microsoftwindows_xp*cpe:2.3:o:microsoft:windows_xp:*:sp2:x64:*:*:*:*:*
microsoftwindows_xp*cpe:2.3:o:microsoft:windows_xp:*:sp3:*:*:*:*:*:*
microsoftoffice_converter_pack*cpe:2.3:a:microsoft:office_converter_pack:*:*:*:*:*:*:*:*
microsoftoffice_word2002cpe:2.3:a:microsoft:office_word:2002:sp3:*:*:*:*:*:*
microsoftoffice_word2003cpe:2.3:a:microsoft:office_word:2003:sp3:*:*:*:*:*:*
microsoftwordpad*cpe:2.3:a:microsoft:wordpad:*:*:*:*:*:*:*:*
microsoftworks8.5cpe:2.3:a:microsoft:works:8.5:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.941

Percentile

99.2%