CVE-2009-2493 is a critical vulnerability in Microsoft's Active Template Library (ATL) affecting various versions of Visual Studio, Visual C++, and Windows operating systems. It allows remote attackers to execute arbitrary code by crafting an HTML document that leverages the OleLoadFromStream function to instantiate objects from data streams, bypassing security policies. This vulnerability has a CVSS score of 9.3, indicating a severe risk. It can be exploited remotely with medium attack complexity and could lead to complete compromise of confidentiality, integrity, and availability of affected systems. Despite its high severity, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. The vulnerability has also received minimal community discussion or media coverage, suggesting a low profile in the threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2005CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_c\+\+:2005:sp1:*:*:*:*:*:* | ||
2008CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_c\+\+:2008:*:*:*:*:*:*:* | ||
2008CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_c\+\+:2008:sp1:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
OpenOffice.org 3 for Windows bundles a vulnerable version of MSVC Runtime
OpenOffice.org 3 for Windows bundles a vulnerable version of MSVC Runtime
OpenOffice.org 3 for Windows bundles a vulnerable version of MSVC Runtime
OpenOffice.org 3 for Windows bundles a vulnerable version of MSVC Runtime