2024-07-14 02:06:08 +00:00

145 lines
5.7 KiB
JSON

{
"id": "CVE-2009-0562",
"sourceIdentifier": "secure@microsoft.com",
"published": "2009-08-12T17:30:00.390",
"lastModified": "2018-10-12T21:50:42.663",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 does not properly allocate memory, which allows remote attackers to execute arbitrary code via unspecified vectors that trigger \"system state\" corruption, aka \"Office Web Components Memory Allocation Vulnerability.\""
},
{
"lang": "es",
"value": "El control Office Web Components ActiveX en Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 para el 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 y 2006 SP1, y Office Small Business Accounting 2006, no asignan memoria adecuadamente, lo que permite a atacantes remotos la ejecuci\u00f3n de c\u00f3digo de su elecci\u00f3n a trav\u00e9s de vectores no especificados que lanzan una corrupci\u00f3n en el estado del sistema (System state), tambi\u00e9n conocida como \"Vulnerabilidad de asignaci\u00f3n de memoria en Office Web Components\"."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 9.3
},
"baseSeverity": "HIGH",
"exploitabilityScore": 8.6,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-399"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:isa_server:2004:sp3:enterprise:*:*:*:*:*",
"matchCriteriaId": "12FAB1BC-F8FB-4A14-8E38-703CF8E67B7D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:isa_server:2004:sp3:standard:*:*:*:*:*",
"matchCriteriaId": "BB4F1038-F652-4A76-874F-3FFAAF30AB93"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:isa_server:2006:sp1:enterprise:*:*:*:*:*",
"matchCriteriaId": "64E8FCC6-B44E-4FA3-AE9E-9FB196D7CD7C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:isa_server:2006:sp1:standard:*:*:*:*:*",
"matchCriteriaId": "91E957DC-91B8-470A-808C-9B2EA687B2A8"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:office:-:*:small_business_accounting_2006:*:*:*:*:*",
"matchCriteriaId": "F27860CB-929A-47F3-801E-3E69C53FA353"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:*",
"matchCriteriaId": "A332D04D-CC8C-4F68-A261-BA2F2D8EAD1E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*",
"matchCriteriaId": "79BA1175-7F02-4435-AEA6-1BA8AADEB7EF"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:office_web_components:2000:sp3:*:*:*:*:*:*",
"matchCriteriaId": "D86088BB-C81D-4CCE-B7D1-1280818D99A2"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:office_web_components:2003:sp1:2007_microsoft_office:*:*:*:*:*",
"matchCriteriaId": "7B654504-9098-4F7F-8CE7-696CF15BCA38"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:office_web_components:2003:sp3:*:*:*:*:*:*",
"matchCriteriaId": "0A9C5BA7-0ECB-4101-9DAD-ECAA42C9E0A3"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:office_web_components:xp:sp3:*:*:*:*:*:*",
"matchCriteriaId": "B07BEA1E-F032-4E63-8548-C98DD6E05AAA"
}
]
}
]
}
],
"references": [
{
"url": "http://www.securitytracker.com/id?1022708",
"source": "secure@microsoft.com"
},
{
"url": "http://www.us-cert.gov/cas/techalerts/TA09-223A.html",
"source": "secure@microsoft.com",
"tags": [
"US Government Resource"
]
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-043",
"source": "secure@microsoft.com"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6337",
"source": "secure@microsoft.com"
}
]
}