RULE(RULE ID:315350)

Rule General Information
Release Date: 2017-02-15
Rule Name: FILE-OFFICE Microsoft Office Project Memory Validation Code Execution Vulnerability -2 (CVE-2009-0102)
Severity:
CVE ID:
Rule Protection Details
Description: Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka "Project Memory Validation Vulnerability."
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows
Reference: http://www.microsoft.com/technet/security/Bulletin/MS09-074.mspx
Solutions
Microsoft has released a patch MS09-074 to eliminate the vulnerability. The patch can be downloaded at http://www.microsoft.com/technet/security/Bulletin/MS09-074.mspx