CVE-2009-2518
CVSS Score Not Available
49.42%
MEDIUM RiskEPSS (98th percentile)
Integer overflow in GDI+ in Microsoft Office XP SP3 allows remote attackers to execute arbitrary code via an Office document with a bitmap (aka BMP) image that triggers memory corruption, aka "Office BMP Integer Overflow Vulnerability."
Published: 10/14/2009
Modified: 4/9/2025
Vulnerability Summary
EPSS Score (Exploitation Probability)
49.42%MEDIUM Exploitation Risk
98th percentile
This vulnerability has a 49.42% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.