SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2009-0556

Microsoft Office PowerPoint Code Injection Vulnerability

KEVHIGH 8.8EPSS 67.5%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 28 January 2026). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Memory Corruption Vulnerability."

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
67.54% probability · 99th percentile
CISA KEV
Listed 7 January 2026 · due 28 January 2026
Weakness
CWE-94
Affected
microsoft/office powerpoint · microsoft/powerpoint
Source
secure@microsoft.com

CISA notes

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://learn.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-017 ; https://nvd.nist.gov/vuln/detail/CVE-2009-0556

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.