Junglewise Threat Intelligence

CVE-2009-0563: Microsoft Office Buffer Overflow Vulnerability

CVE-2009-0563 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-06-08

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

A stack-based buffer overflow vulnerability exists in multiple versions of Microsoft Office Word and related components. Remote attackers can execute arbitrary code by tricking a user into opening a specially crafted Word document containing a tag with an invalid length field.

Affected products

  • Microsoft Office Word 2002 SP3
  • Microsoft Office Word 2003 SP3
  • Microsoft Office Word 2007 SP1, SP2
  • Microsoft Office for Mac 2004
  • Microsoft Office for Mac 2008
  • Microsoft Open XML File Format Converter for Mac
  • Microsoft Office Word Viewer 2003 SP3
  • Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1, SP2

Timeline

  • 2009-06-09: patched: Microsoft Security Bulletin MS09-027 published.
  • 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-06-08: disclosed: NVD publication date.

Related threats