CVE-2009-1533

CWE-119Buffer Overflow3 documents3 sources
Severity
9.3CRITICAL
EPSS
72.9%
top 1.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 10
Latest updateMay 2

Description

Buffer overflow in the Works for Windows document converters in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, Office 2007 SP1, and Works 8.5 and 9 allows remote attackers to execute arbitrary code via a crafted Works .wps file that triggers memory corruption, aka "File Converter Buffer Overflow Vulnerability."

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages3 packages

NVDmicrosoft/office2000, 2003+1
NVDmicrosoft/works8.5, 9.0+1

🔴Vulnerability Details

2
GHSA
GHSA-h8q6-mwvg-c9mq: Buffer overflow in the Works for Windows document converters in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, Office 2007 SP1, and Works2022-05-02
CVEList
CVE-2009-1533: Buffer overflow in the Works for Windows document converters in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, Office 2007 SP1, and Works2009-06-10
CVE-2009-1533 (CRITICAL CVSS 9.3) | Buffer overflow in the Works for Wi | cvebase.io