2024-05-26 14:27:05 +02:00
### [CVE-2009-2518](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2518)

2025-09-29 21:09:30 +02:00


2024-05-26 14:27:05 +02:00
### Description
Integer overflow in GDI+ in Microsoft Office XP SP3 allows remote attackers to execute arbitrary code via an Office document with a bitmap (aka BMP) image that triggers memory corruption, aka "Office BMP Integer Overflow Vulnerability."
### POC
#### Reference
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-062
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6430
#### Github
2025-09-29 21:09:30 +02:00
- https://github.com/ARPSyndicate/cve-scores
2024-05-26 14:27:05 +02:00