CVE-2009-3678 describes an integer overflow in the Canonical Display Driver (cdd.dll) affecting 64-bit Windows 7 and Server 2008 R2 systems with the Aero theme enabled. This vulnerability allows an attacker to cause a denial of service (system reboot) or potentially execute arbitrary code by crafting an image file that triggers incorrect data parsing during user-to-kernel mode data transfer. With a CVSS score of 9.3, this is a critical vulnerability, requiring medium attack complexity but no authentication, and can lead to complete compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:*:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:*:x64:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.