CVE-2009-2504 describes multiple integer overflows within unspecified GDI+ APIs across numerous Microsoft products, including various .NET Framework versions, Windows operating systems, Office suites, and SQL Server components. This critical vulnerability allows remote attackers to execute arbitrary code by enticing a user to open a crafted XAML browser application (XBAP), ASP.NET application, or .NET Framework application. With a CVSS score of 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C), it represents a high-risk threat due to its network-based attack vector, medium attack complexity, and complete compromise of confidentiality, integrity, and availability. While the FAUCET Risk Score is 97/100, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, suggesting it is not currently a prominent threat in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:*:sp2:itanium:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:*:sp2:x64:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:*:*:itanium:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:*:*:x32:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.