CVE-2009-0202 is a critical vulnerability affecting Microsoft PowerPoint 2000 and 2002, specifically within the FL21WIN.DLL component of the PowerPoint Freelance Windows 2.1 Translator. It involves an array index error that can lead to a heap-based buffer overflow when processing specially crafted Freelance files containing malicious layout information. This flaw carries a CVSS score of 9.3, indicating a severe risk where remote attackers can achieve complete compromise (confidentiality, integrity, and availability) with medium attack complexity and no authentication required. Despite its high severity and potential for arbitrary code execution, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2000CPE matchmatch criteria | cpe:2.3:a:microsoft:office_powerpoint:2000:*:*:*:*:*:*:* | ||
2002CPE matchmatch criteria | cpe:2.3:a:microsoft:office_powerpoint:2002:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.