CyberRota
Live Feed
Return to register
Case File

CVE-2009-1925

HIGH · CVSS 10 EPSS 27.40% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-09-08 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

Exhibit — Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2009-1925
Severity
HIGH
CVSS
10
EPSS
27.40%
Microsoft Windows

Original Filing — NVD Description

The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly manage state information, which allows remote attackers to execute arbitrary code by sending packets to a listening service, and thereby triggering misinterpretation of an unspecified field as a function pointer, aka "TCP/IP Timestamps Code Execution Vulnerability."