Junglewise Threat Intelligence

CVE-2009-0557: Microsoft Office Object Record Corruption Vulnerability

CVE-2009-0557 · Severity: critical · CVSS 9.3 · Exploited in the wild · Published 2022-06-08

Technologies: Microsoft Office, Microsoft Excel. Vendors: Microsoft.

Executive brief

Microsoft Excel and related Office components contain an object record corruption vulnerability. Remote attackers can execute arbitrary code by tricking a user into opening a specially crafted Excel file containing a malformed record object.

Affected products

  • Microsoft Excel 2000 SP3, XP SP3, 2003 SP3, 2007 SP1, 2007 SP2
  • Microsoft Excel for Mac 2004, 2008
  • Microsoft Office Excel Viewer 2003 SP3, and unversioned
  • Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1, SP2
  • Microsoft Open XML File Format Converter for Mac
  • Microsoft Office SharePoint Server 2007 SP1, SP2

Timeline

  • 2009-06-09: patched: Microsoft released security bulletin MS09-021.
  • 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-06-08: disclosed: NVD publication date.
  • exploited: Reported as exploited in the wild.

Related threats