First published: Wed Aug 12 2009(Updated: )
Heap-based buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 allows remote attackers to execute arbitrary code via unspecified parameters to unknown methods, aka "Office Web Components Heap Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Visual Studio | =2003-sp1 | |
Microsoft Office Web Components | =2000-sp3 | |
Microsoft BizTalk Server | =2002 | |
Microsoft Office Web Components | =xp-sp3 | |
Microsoft Office | =xp-sp3 | |
McAfee SecurityShield for Microsoft ISA Server | =2004-sp3 | |
Microsoft Office Web Components | =2003-sp1 | |
McAfee SecurityShield for Microsoft ISA Server | =2006-sp1 | |
Microsoft Office | ||
McAfee SecurityShield for Microsoft ISA Server | =2006-sp1 | |
Microsoft Office Web Components | =2003-sp3 | |
Microsoft Office | =2003-sp3 | |
McAfee SecurityShield for Microsoft ISA Server | =2004-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE-2009-2496 vulnerability is classified as high severity due to the potential for remote code execution.
To fix CVE-2009-2496, it is recommended to update Microsoft Office and related components to the latest security patches provided by Microsoft.
CVE-2009-2496 affects several Microsoft applications, including Office Web Components, Microsoft Office XP, and Microsoft Internet Security and Acceleration Server.
Yes, CVE-2009-2496 can be exploited remotely, allowing an attacker to execute arbitrary code on the affected system.
CVE-2009-2496 is a heap-based buffer overflow vulnerability that can lead to security breaches in affected software.