CVE-2009-0202: Code Injection
Published Jun 11, 2009
·Updated
Array index error in FL21WIN.DLL in the PowerPoint Freelance Windows 2.1 Translator in Microsoft PowerPoint 2000 and 2002 allows remote attackers to execute arbitrary code via a Freelance file with unspecified "layout information" that triggers a heap-based buffer overflow.
Affected Software
2 affected components
Microsoft Office PowerPoint=2000
Microsoft Office PowerPoint=2002
Event History
Jun 11, 2009
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-0202?
The severity of CVE-2009-0202 is considered critical due to its potential for remote code execution.
2
How do I fix CVE-2009-0202?
To fix CVE-2009-0202, install the relevant security patches released by Microsoft for PowerPoint 2000 and 2002.
3
What versions of PowerPoint are affected by CVE-2009-0202?
CVE-2009-0202 affects Microsoft PowerPoint 2000 and 2002.
4
What type of vulnerability is CVE-2009-0202?
CVE-2009-0202 is a heap-based buffer overflow caused by an array index error.
5
Can CVE-2009-0202 be exploited remotely?
Yes, CVE-2009-0202 can be exploited remotely via a specially crafted Freelance file.