CyberSec.Space Logo
Back to CVE Browser

CVE-2009-0086

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0560%
EPSS Percentile10.10th
PublishedApr 15, 2009
Last ModifiedApr 23, 2026

Vulnerability Description

Integer underflow in Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote HTTP servers to execute arbitrary code via crafted parameter values in a response, related to error handling, aka "Windows HTTP Services Integer Underflow Vulnerability."

Affected Platforms (CPE)

πŸ’»
Microsoft

Windows 2000

All versions
πŸ’»
Microsoft

Windows Server 2003

All versions
πŸ’»
Microsoft

Windows Server 2003

All versions
πŸ’»
Microsoft

Windows Server 2003

All versions
πŸ’»
Microsoft

Windows Server 2003

All versions
πŸ’»
Microsoft

Windows Server 2008

All versions
πŸ’»
Microsoft

Windows Server 2008

All versions
πŸ’»
Microsoft

Windows Server 2008

All versions
πŸ’»
Microsoft

Windows Server 2008

All versions
πŸ’»
Microsoft

Windows Vista

All versions
πŸ’»
Microsoft

Windows Vista

All versions
πŸ’»
Microsoft

Windows Vista

All versions
πŸ’»
Microsoft

Windows Vista

= gold
πŸ’»
Microsoft

Windows Xp

All versions
πŸ’»
Microsoft

Windows Xp

All versions

References & Advisories

Related Vulnerabilities