CVE-2009-1131
 
Severity Score
9.3
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Multiple stack-based buffer overflows in Microsoft Office PowerPoint 2000 SP3 allow remote attackers to execute arbitrary code via a large amount of data associated with unspecified atoms in a PowerPoint file that triggers memory corruption, aka "Data Out of Bounds Vulnerability."
Múltiples desbordamientos del búfer basados en pila en Microsoft Office PowerPoint 2000 SP3 permite a atacantes remotos ejecutar código de su elección a través de una cantidad grande de datos asociados con átomos sin especificar en un fichero PowerPoint que provoca una corrupción de memoria, también conocido como "Vulnerabilidad de datos fuera de los límites"
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2009-03-25 CVE Reserved
- 2009-05-12 CVE Published
- 2024-08-07 CVE Updated
- 2024-11-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://osvdb.org/54393 | Vdb Entry | |
http://www.securityfocus.com/archive/1/503451 | Mailing List | |
http://www.securityfocus.com/bid/34841 | Vdb Entry | |
http://www.securitytracker.com/id?1022205 | Vdb Entry | |
http://www.us-cert.gov/cas/techalerts/TA09-132A.html | Third Party Advisory | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5351 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/32428 | 2018-10-12 | |
http://secunia.com/secunia_research/2008-46 | 2018-10-12 | |
http://www.vupen.com/english/advisories/2009/1290 | 2018-10-12 | |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-017 | 2018-10-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Office Powerpoint Search vendor "Microsoft" for product "Office Powerpoint" | 2000 Search vendor "Microsoft" for product "Office Powerpoint" and version "2000" | sp3 |
Affected
|