CVE-2009-2506: Buffer Overflow
Integer overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3; Works 8.5; Office Converter Pack; and WordPad in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a DOC file with an invalid number of property names in the DocumentSummaryInformation stream, which triggers a heap-based buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2506?
CVE-2009-2506 is rated as a critical vulnerability due to its ability to allow remote code execution.
How do I fix CVE-2009-2506?
To fix CVE-2009-2506, users should apply the latest security updates released by Microsoft for the affected software versions.
Which versions of Microsoft Office are affected by CVE-2009-2506?
Microsoft Office Word 2002 SP3, Microsoft Office Word 2003 SP3, and Microsoft Office Converter Pack are affected by CVE-2009-2506.
Which operating systems are impacted by CVE-2009-2506?
CVE-2009-2506 impacts Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2.
What types of attacks leverage CVE-2009-2506?
CVE-2009-2506 can be exploited by attackers through specially crafted DOC files that trigger the integer overflow vulnerability.