cbcvebase.
CVE-2009-0102
published 2009-12-09

CVE-2009-0102: Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote…

PriorityP353critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
23.50%
97.5th percentile
Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka "Project Memory Validation Vulnerability."

Affected

4 ranges
VendorProductVersion rangeFixed in
microsoftoffice_project
microsoftproject_portfolio_server
microsoftproject_server
microsoftproject_server
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.