Vulnerability Name: | CVE-2009-1534 (CCN-51454) | ||||||||
Assigned: | 2009-08-11 | ||||||||
Published: | 2009-08-11 | ||||||||
Updated: | 2018-10-12 | ||||||||
Summary: | Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3, Office XP Web Components SP3, BizTalk Server 2002, and Visual Studio .NET 2003 SP1 allows remote attackers to execute arbitrary code via crafted property values, aka "Office Web Components Buffer Overflow Vulnerability." | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 7.7 High (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
7.7 High (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-119 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-1534 Source: OSVDB Type: UNKNOWN 56916 Source: CCN Type: SECTRACK ID: 1022708 Microsoft Office Web Components Buffer Overflows in ActiveX Control Let Remote Users Execute Arbitrary Code Source: CCN Type: Microsoft Security Bulletin MS09-043 Vulnerabilities in Microsoft Office Web Components Could Allow Remote Code Execution (957638) Source: CCN Type: OSVDB ID: 56916 Microsoft Office Web Components HTMLURL Parameter ActiveX Spreadsheet Object Handling Overflow Source: BID Type: Patch 35992 Source: CCN Type: BID-35992 Microsoft Office Web Components ActiveX Control Stack Buffer Overflow Code Execution Vulnerability Source: SECTRACK Type: UNKNOWN 1022708 Source: CERT Type: US Government Resource TA09-223A Source: MS Type: UNKNOWN MS09-043 Source: XF Type: UNKNOWN ms-officeweb-bo(51454) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:6326 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |