Junglewise Threat Intelligence

CVE-2009-3129: Microsoft Excel Featheader Record Memory Corruption Vulnerability

CVE-2009-3129 · Severity: critical · CVSS 9.3 · Exploited in the wild · Published 2022-03-03

Technologies: Microsoft Excel. Vendors: Microsoft.

Executive brief

Microsoft Excel is vulnerable to memory corruption when processing a FEATHEADER record with an invalid cbHdrData size element. This flaw affects the pointer offset calculation, allowing remote attackers to execute arbitrary code via a specially crafted spreadsheet.

Affected products

  • Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP1, 2007 SP2
  • Microsoft Office for Mac 2004, 2008
  • Microsoft Open XML File Format Converter for Mac
  • Microsoft Excel Viewer 2003 SP3
  • Microsoft Excel Viewer SP1, SP2
  • Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1, SP2

Timeline

  • 2009-11-10: advisory: Microsoft Security Bulletin MS09-067 published
  • 2009-11-10: patched
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-03: disclosed: NVD publication date listed in advisory

Related threats