CVE-2009-0102

Microsoft Office Project - Remote Code Execution via Malformed Project File

Title source: llm
STIX 2.1

Description

Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka "Project Memory Validation Vulnerability."

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6298
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA09-342A.html

Scores

EPSS 0.2350
EPSS Percentile 97.6%

Details

CWE
CWE-399
Status published
Products (4)
microsoft/office_project 2007 sp1 (2 CPE variants)
microsoft/project_portfolio_server 2007 sp1 (2 CPE variants)
microsoft/project_server 2003 sp3
microsoft/project_server 2007 sp1 (2 CPE variants)
Published Dec 09, 2009
Tracked Since Feb 18, 2026