The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory locations via a crafted RPC message that triggers incorrect pointer reading, related to "IDL interfaces containing a non-conformant varying array" and FC_SMVARRAY, FC_LGVARRAY, FC_VARIABLE_REPEAT, and FC_VARIABLE_OFFSET, aka "RPC Marshalling Engine Vulnerability."
Published Jun 10, 2009
10.0
HIGHCVSS 2.0
EPSS 32.39%
Description
The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory locations via a crafted RPC message that triggers incorrect pointer reading, related to "IDL interfaces containing a non-conformant varying array" and FC_SMVARRAY, FC_LGVARRAY, FC_VARIABLE_REPEAT, and FC_VARIABLE_OFFSET, aka "RPC Marshalling Engine Vulnerability."
Affected products
No data.
- n/a
- n/a
- n/a
- n/a
- 2008
- 2008
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (28 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 32.39% (0.32387) | 98.29th | v5 (v2026.06.15) |
| Jun 15, 2026 | 32.39% (0.32387) | 98.10th | v5 (v2026.06.15) |
| Dec 28, 2025 | 56.25% (0.56246) | 98.00th | v4 (v2025.03.14) |
| Dec 27, 2025 | 52.52% (0.52524) | 97.84th | v4 (v2025.03.14) |
| Oct 30, 2025 | 56.01% (0.56005) | 97.97th | v4 (v2025.03.14) |
| Oct 28, 2025 | 58.34% (0.58345) | 98.08th | v4 (v2025.03.14) |
| Oct 27, 2025 | 54.70% (0.54703) | 97.91th | v4 (v2025.03.14) |
| Oct 1, 2025 | 58.34% (0.58345) | 98.15th | v4 (v2025.03.14) |
| Mar 30, 2025 | 54.70% (0.54703) | 97.83th | v4 (v2025.03.14) |
| Mar 29, 2025 | 58.39% (0.58388) | 97.41th | v4 (v2025.03.14) |
| Mar 17, 2025 | 54.70% (0.54703) | 97.79th | v4 (v2025.03.14) |
| Jan 24, 2025 | 31.11% (0.31112) | 97.02th | v3 (v2023.03.01) |
| Dec 19, 2024 | 38.40% (0.38401) | 97.24th | v3 (v2023.03.01) |
| Dec 17, 2024 | 46.10% (0.46101) | 97.50th | v3 (v2023.03.01) |
| Nov 13, 2024 | 13.45% (0.13453) | 95.75th | v3 (v2023.03.01) |
| Oct 7, 2024 | 17.87% (0.17869) | 96.24th | v3 (v2023.03.01) |
| May 17, 2024 | 23.28% (0.23280) | 96.54th | v3 (v2023.03.01) |
| Dec 9, 2023 | 28.99% (0.28988) | 96.41th | v3 (v2023.03.01) |
| Oct 28, 2023 | 32.58% (0.32584) | 96.52th | v3 (v2023.03.01) |
| Jul 29, 2023 | 39.99% (0.39989) | 96.75th | v3 (v2023.03.01) |
| Mar 7, 2023 | 25.85% (0.25854) | 95.94th | v3 (v2023.03.01) |
| Mar 6, 2023 | 20.65% (0.20648) | 96.51th | v2 (v2022.01.01) |
| Sep 10, 2022 | 20.65% (0.20648) | 96.34th | v2 (v2022.01.01) |
| Jul 18, 2022 | 24.38% (0.24379) | 96.67th | v2 (v2022.01.01) |
| Jul 17, 2022 | 1.41% (0.01408) | 71.80th | v2 (v2022.01.01) |
| May 5, 2022 | 24.38% (0.24379) | 96.61th | v2 (v2022.01.01) |
| Mar 1, 2022 | 26.11% (0.26113) | 95.72th | v2 (v2022.01.01) |
| Feb 4, 2022 | 35.31% (0.35309) | 96.80th | v2 (v2022.01.01) |
References (8)
- http://blogs.technet.com/srd/archive/2009/06/09/ms09-026-how-a-developer-can-know-if-their-rpc-interface-is-affected.aspx x_refsource_CONFIRMVendor Advisory
- http://osvdb.org/54936 vdb-entryx_refsource_OSVDBBroken Link
- http://www.securityfocus.com/bid/35219 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1022357 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://www.us-cert.gov/cas/techalerts/TA09-160A.html third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource
- http://www.vupen.com/english/advisories/2009/1545 vdb-entryx_refsource_VUPENThird Party Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-026 vendor-advisoryx_refsource_MS
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6227 vdb-entrysignaturex_refsource_OVALThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://blogs.technet.com/srd/archive/2009/06/09/ms09-026-how-a-developer-can-know-if-their-rpc-interface-is-affected.aspx | x_refsource_CONFIRMVendor Advisory | |
| http://osvdb.org/54936 | vdb-entryx_refsource_OSVDBBroken Link | |
| http://www.securityfocus.com/bid/35219 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id?1022357 | vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry | |
| http://www.us-cert.gov/cas/techalerts/TA09-160A.html | third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource | |
| http://www.vupen.com/english/advisories/2009/1545 | vdb-entryx_refsource_VUPENThird Party Advisory | |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-026 | vendor-advisoryx_refsource_MS | |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6227 | vdb-entrysignaturex_refsource_OVALThird Party Advisory |
Change history (0)
No recorded changes yet.