AUGUST 5, 2026
Live Feed
Back to database
Case File

CVE-2009-2493

HIGH · CVSS 8.8 EPSS 37.90%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-07-29 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.8. It affects Microsoft, Windows. Its EPSS score suggests a 37.9% probability of exploitation in the next 30 days. It may be remotely exploitable.

CVE
CVE-2009-2493
Severity
HIGH
CVSS
8.8
EPSS
37.90%
Microsoft Windows

Original NVD Description

The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not properly restrict use of OleLoadFromStream in instantiating objects from data streams, which allows remote attackers to execute arbitrary code via a crafted HTML document with an ATL (1) component or (2) control, related to ATL headers and bypassing security policies, aka "ATL COM Initialization Vulnerability."