CVE-2009-0223
iDEFENSE Security Advisory 2009-05-12.2
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0226, CVE-2009-0227, and CVE-2009-1137.
Microsoft Office PowerPoint 2000 SP3, 2002 SP3, ay 2003 SP3 permite a atacantes remotos ejecutar código de su elección a través de datos de sonido manipulados en un fichero que utiliza un formato de fichero nativo en PowerPoint 4.0, que lleva a una corrupción de memoria, también conocido como "Vulnerabilidad de formato de fichero legado" una vulnerabilidad diferente a CVE-2009-0222, CVE-2009-0226, CVE-2009-0227, y CVE-2009-1137.
Remote exploitation of a heap corruption vulnerability in Microsoft Corp.'s PowerPoint could allow an attacker to execute arbitrary code with the privileges of the current user. In particular, there is code that parses structures in the PowerPoint file. If the number of these structures is greater than a certain value, then memory corruption will occur. This memory corruption leads to the executing of arbitrary code. iDefense has confirmed the existence of these vulnerabilities in PowerPoint 2000 SP3 and XP SP3.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-01-20 CVE Reserved
- 2009-05-12 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/32428 | Third Party Advisory | |
http://www.securityfocus.com/bid/34834 | Vdb Entry | |
http://www.securitytracker.com/id?1022205 | Vdb Entry | |
http://www.us-cert.gov/cas/techalerts/TA09-132A.html | Third Party Advisory | |
http://www.vupen.com/english/advisories/2009/1290 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6269 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-017 | 2018-10-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Office Powerpoint Search vendor "Microsoft" for product "Office Powerpoint" | 2000 Search vendor "Microsoft" for product "Office Powerpoint" and version "2000" | sp3 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Office Powerpoint Search vendor "Microsoft" for product "Office Powerpoint" | 2002 Search vendor "Microsoft" for product "Office Powerpoint" and version "2002" | sp3 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Office Powerpoint Search vendor "Microsoft" for product "Office Powerpoint" | 2003 Search vendor "Microsoft" for product "Office Powerpoint" and version "2003" | sp3 |
Affected
|