Skip to main content

CVE-2009-2518

CVSS Score Not Available
49.42%
MEDIUM RiskEPSS (98th percentile)

Integer overflow in GDI+ in Microsoft Office XP SP3 allows remote attackers to execute arbitrary code via an Office document with a bitmap (aka BMP) image that triggers memory corruption, aka "Office BMP Integer Overflow Vulnerability."

Published: 10/14/2009
Modified: 4/9/2025
Back to CVE Lookup

Vulnerability Summary

EPSS Score (Exploitation Probability)

49.42%MEDIUM Exploitation Risk
98th percentile

This vulnerability has a 49.42% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.