CVE-2009-0556

Confirmed PUBLISHED

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute...

Microsoft · Office PowerPoint

6269 days faster than CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.8 High EPSS 67.5%

At a Glance

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Memory Corruption Vulnerability."

cisa windows microsoft
CVE Published
Apr 03, 2009
Exploitation Reported
Apr 03, 2009
CVSS
8.8 High
EPSS
67.5%
Remote Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • MS09-017 docs.microsoft.com · Vendor Advisory https://docs.microsoft.com/en-us/security-updates/securitybulletins/2...
  • 34572 secunia.com · Third-Party Advisory http://secunia.com/advisories/34572
  • TA09-132A us-cert.gov · Third-Party Advisory http://www.us-cert.gov/cas/techalerts/TA09-132A.html
  • VU#627331 kb.cert.org · Third-Party Advisory http://www.kb.cert.org/vuls/id/627331
  • ADV-2009-1290 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2009/1290
Show 13 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.