Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2009-4311

Quick assessment

Affected
n/a n/a
Exploitation
High exploitation probability; assess promptly
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Microsoft Windows 2000 SP4, XP SP2和SP3,以及Server 2003 SP2版本中的Indeo codec存在未明漏洞,远程攻击者可以借助人工多媒体目录执行任意代码,比如NGS软件的Paul Byrne引起的Microsoft。

AI Predicted 9.8 Difficulty: Easy EPSS 21.95% · P98
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2009-4311

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted media content, as reported to Microsoft by Paul Byrne of NGS Software. NOTE: this might overlap CVE-2008-3615.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Microsoft Windows 2000 Indeo codec人工多媒体目录未明漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft Windows 2000 SP4, XP SP2和SP3,以及Server 2003 SP2版本中的Indeo codec存在未明漏洞,远程攻击者可以借助人工多媒体目录执行任意代码,比如NGS软件的Paul Byrne引起的Microsoft。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2009-4311

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2009-4311

登录查看更多情报信息。

Vendor Advisories for CVE-2009-4311 (9)

Other References for CVE-2009-4311 (1)

Same Patch Batch · n/a · 2009-12-13 · 10 CVEs total

CVE-2009-4131 Linux kernel 权限许可和访问控制问题漏洞
CVE-2009-4210 Microsoft Windows 2000 SP4代码注入漏洞
CVE-2009-4306 Linux kernel ext4 未明漏洞EXT4_IOC_MOVE_EXT ioctl未明拒绝服务漏洞
CVE-2009-4307 Linux kernel 'super.c' ext4_fill_flex_info函数拒绝服务漏洞
CVE-2009-4308 Linux kernel 'super.c'ext4_decode_error函数拒绝服务漏洞
CVE-2009-4309 microsoft windows_media_player 缓冲区溢出漏洞
CVE-2009-4310 Microsoft Windows 2000 Windows Media Player Intel Indeo41 codec人工压缩视频数据堆缓冲溢出漏洞
CVE-2009-4312 Microsoft Windows 2000 Indeo codec人工多媒体目录未明漏洞
CVE-2009-4313 Microsoft Windows 2000 Indeo32 codec畸形数据拒绝服务漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2009-4311

No comments yet


Leave a comment