CVE-2009-1533

N/A Unknown
Published: June 10, 2009 Modified: April 23, 2026
View on NVD

Description

Buffer overflow in the Works for Windows document converters in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, Office 2007 SP1, and Works 8.5 and 9 allows remote attackers to execute arbitrary code via a crafted Works .wps file that triggers memory corruption, aka "File Converter Buffer Overflow Vulnerability."

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://osvdb.org/54939
Source: secure@microsoft.com
http://secunia.com/advisories/35371
Source: secure@microsoft.com
http://www.securityfocus.com/bid/35184
Source: secure@microsoft.com
http://www.securitytracker.com/id?1022354
Source: secure@microsoft.com
http://www.securitytracker.com/id?1022355
Source: secure@microsoft.com
http://www.us-cert.gov/cas/techalerts/TA09-160A.html
Source: secure@microsoft.com
US Government Resource
http://blogs.technet.com/srd/archive/2009/06/09/ms09-024.aspx
Source: af854a3a-2127-422b-91ae-364da2661108
http://jvn.jp/en/jp/JVN70858401/index.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/54939
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/35371
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/35184
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1022354
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1022355
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.us-cert.gov/cas/techalerts/TA09-160A.html
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
http://www.vupen.com/english/advisories/2009/1543
Source: af854a3a-2127-422b-91ae-364da2661108

22 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
72.9%
99th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

microsoft