CVE-2009-0228
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Stack-based buffer overflow in the EnumeratePrintShares function in Windows Print Spooler Service (win32spl.dll) in Microsoft Windows 2000 SP4 allows remote printer servers to execute arbitrary code via a crafted ShareName in a response to an RPC request, related to "printing data structures," aka "Buffer Overflow in Print Spooler Vulnerability."
Desbordamiento de buffer basado en pila en la función EnumeratePrintShares en Windows Print Spooler Service (win32spl.dll) en Microsoft Windows 2000 SP4 permite a servidores de impresión remotos ejecutar código arbitrario a través de un ShareName manipulado en respuesta a una petición RPC, relacionado con "estructuras de datos impresos", también conocido como "Buffer Overflow in Print Spooler Vulnerability."
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-01-20 CVE Reserved
- 2009-06-10 CVE Published
- 2024-08-07 CVE Updated
- 2024-11-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=806 | Third Party Advisory | |
http://osvdb.org/54932 | Vdb Entry | |
http://secunia.com/advisories/35365 | Third Party Advisory | |
http://support.avaya.com/elmodocs2/security/ASA-2009-217.htm | X_refsource_confirm | |
http://www.securityfocus.com/bid/35206 | Vdb Entry | |
http://www.securitytracker.com/id?1022352 | Vdb Entry | |
http://www.us-cert.gov/cas/techalerts/TA09-160A.html | Third Party Advisory | |
http://www.vupen.com/english/advisories/2009/1541 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6317 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-022 | 2018-10-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Windows 2000 Search vendor "Microsoft" for product "Windows 2000" | * | sp4 |
Affected
|