CVE-2009-2528: Code Injection
GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2528?
CVE-2009-2528 is rated as critical due to the potential for remote code execution.
How do I fix CVE-2009-2528?
To fix CVE-2009-2528, apply the security update provided by Microsoft for affected software versions.
What software is affected by CVE-2009-2528?
CVE-2009-2528 affects Microsoft Office XP SP3 and various Microsoft Windows versions including Windows 2003 and Windows XP.
What type of vulnerability is CVE-2009-2528?
CVE-2009-2528 is a memory corruption vulnerability in GDI+ that can be exploited through specially crafted Office documents.
Can CVE-2009-2528 be exploited remotely?
Yes, CVE-2009-2528 can be exploited remotely, allowing attackers to execute arbitrary code on the target system.