CVE-2009-0215 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 36.3% (pctl 98)
Patch early
A public exploit exists.
Description
Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo computers, allows remote attackers to execute arbitrary code via unspecified vectors.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 36.31% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-03-25 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| ibm | access support activex control |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | IBM Access Support - ActiveX Control Buffer Overflow (Metasploit) | 2010-11-11 |
References
- http://osvdb.org/52958
- http://secunia.com/advisories/34470
- http://www.kb.cert.org/vuls/id/340420
- http://www.securityfocus.com/bid/34228
- http://www.vupen.com/english/advisories/2009/0824
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49409
- http://osvdb.org/52958
- http://secunia.com/advisories/34470
- http://www.kb.cert.org/vuls/id/340420
- http://www.securityfocus.com/bid/34228
- http://www.vupen.com/english/advisories/2009/0824
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49409
→ the Explorer · watch your stack · NVD