CVE-2009-0556
Microsoft Office PowerPoint Code Injection Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 28 January 2026). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Memory Corruption Vulnerability."
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 67.54% probability · 99th percentile
- CISA KEV
- Listed 7 January 2026 · due 28 January 2026
- Weakness
- CWE-94
- Affected
- microsoft/office powerpoint · microsoft/powerpoint
- Source
- secure@microsoft.com
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://learn.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-017 ; https://nvd.nist.gov/vuln/detail/CVE-2009-0556
References
- http://blogs.technet.com/mmpc/archive/2009/04/02/new-0-day-exploits-using-powerpoint-files.aspxVendor Advisory
- http://blogs.technet.com/msrc/archive/2009/04/02/microsoft-security-advisory-969136.aspxVendor Advisory
- http://blogs.technet.com/srd/archive/2009/04/02/investigating-the-new-powerpoint-issue.aspxVendor Advisory
- http://osvdb.org/53182Broken Link
- http://secunia.com/advisories/34572Vendor Advisory
- http://www.kb.cert.org/vuls/id/627331US Government Resource
- http://www.microsoft.com/technet/security/advisory/969136.mspxPatch, Vendor Advisory
- http://www.securityfocus.com/archive/1/503453/100/0/threadedBroken Link
- http://www.securityfocus.com/bid/34351Broken Link
- http://www.securitytracker.com/id?1021967Broken Link
- http://www.us-cert.gov/cas/techalerts/TA09-132A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2009/0915Vendor Advisory
- http://www.vupen.com/english/advisories/2009/1290Broken Link
- http://www.zerodayinitiative.com/advisories/ZDI-09-019Third Party Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-017Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49632Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6204Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6279Broken Link
- http://blogs.technet.com/mmpc/archive/2009/04/02/new-0-day-exploits-using-powerpoint-files.aspxVendor Advisory
- http://blogs.technet.com/msrc/archive/2009/04/02/microsoft-security-advisory-969136.aspxVendor Advisory
- http://blogs.technet.com/srd/archive/2009/04/02/investigating-the-new-powerpoint-issue.aspxVendor Advisory
- http://osvdb.org/53182Broken Link
- http://secunia.com/advisories/34572Vendor Advisory
- http://www.kb.cert.org/vuls/id/627331US Government Resource
- http://www.microsoft.com/technet/security/advisory/969136.mspxPatch, Vendor Advisory
- http://www.securityfocus.com/archive/1/503453/100/0/threadedBroken Link
- http://www.securityfocus.com/bid/34351Broken Link
- http://www.securitytracker.com/id?1021967Broken Link
- http://www.us-cert.gov/cas/techalerts/TA09-132A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2009/0915Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.