First published: Wed Oct 14 2009(Updated: )
Integer overflow in GDI+ in Microsoft Office XP SP3 allows remote attackers to execute arbitrary code via an Office document with a bitmap (aka BMP) image that triggers memory corruption, aka "Office BMP Integer Overflow Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =xp-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2518 has a severity rating of critical due to its potential for remote code execution.
To fix CVE-2009-2518, you should apply the appropriate Microsoft security update as outlined in their bulletin.
CVE-2009-2518 affects Microsoft Office XP SP3.
CVE-2009-2518 is an integer overflow vulnerability that can lead to memory corruption.
Yes, CVE-2009-2518 can be exploited by embedding a specially crafted BMP image in an Office document.