RULE(RULE ID:711070)

Rule General Information
Release Date: 2013-05-20
Rule Name: FILE-OFFICE Microsoft Office BMP Header Biclrused Integer Overflow Vulnerability -2 (CVE-2009-2518)
Severity:
CVE ID:
Rule Protection Details
Description: Integer overflow in GDI+ in Microsoft Office XP SP3 allows remote attackers to execute arbitrary code via an Office document with a bitmap (aka BMP) image that triggers memory corruption, aka "Office BMP Integer Overflow Vulnerability."
Impact: An attacker can exploit the affected software with an integer overflow vulnerability. Successful exploit leads to execute arbitrary code, and failed exploit may disturb the software logic and cause denial of service.
Affected OS: Windows
Reference: http://www.microsoft.com/technet/security/Bulletin/MS09-062.mspx
Solutions
Microsoft has released a patch MS09-062 to eliminate the vulnerability. The patch can be downloaded at http://www.microsoft.com/technet/security/Bulletin/MS09-062.mspx