CVE-2009-0102
Published Dec 9, 2009
Last updated 6 years ago
Overview
- Description
- Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka "Project Memory Validation Vulnerability."
- Source
- secure@microsoft.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 9.3
- Impact score
- 10
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-399
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:microsoft:office_project:2007:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2849085E-2340-4B66-A37A-2C673DC257C4" }, { "criteria": "cpe:2.3:a:microsoft:office_project:2007:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7709A711-DAB4-41D6-B6D0-9E535F33CFB8" }, { "criteria": "cpe:2.3:a:microsoft:project_portfolio_server:2007:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "349DD10D-6BA9-4AF0-9BE2-B8F29E826C25" }, { "criteria": "cpe:2.3:a:microsoft:project_portfolio_server:2007:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1D4EBB7F-ECE8-4333-8C97-15443FC17B2C" }, { "criteria": "cpe:2.3:a:microsoft:project_server:2003:sp3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D52BBD51-F67B-4AC7-8C96-7E97A85BBC54" }, { "criteria": "cpe:2.3:a:microsoft:project_server:2007:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AB1D7F2D-FE9F-4BFB-9708-18D1DF8C2F33" }, { "criteria": "cpe:2.3:a:microsoft:project_server:2007:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DF94CD56-427C-4898-BF05-DCEFEF4AE776" } ], "operator": "OR" } ] } ]