Vulnerability Description
Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Memory Corruption Vulnerability."
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Office Powerpoint | 2004 |
| Microsoft | Powerpoint | 2000 |
Related Weaknesses (CWE)
References
- http://blogs.technet.com/mmpc/archive/2009/04/02/new-0-day-exploits-using-powerpVendor Advisory
- http://blogs.technet.com/msrc/archive/2009/04/02/microsoft-security-advisory-969Vendor Advisory
- http://blogs.technet.com/srd/archive/2009/04/02/investigating-the-new-powerpointVendor Advisory
- http://osvdb.org/53182Broken Link
- http://secunia.com/advisories/34572Vendor Advisory
- http://www.kb.cert.org/vuls/id/627331US Government Resource
- http://www.microsoft.com/technet/security/advisory/969136.mspxPatchVendor Advisory
- http://www.securityfocus.com/archive/1/503453/100/0/threadedBroken Link
- http://www.securityfocus.com/bid/34351Broken Link
- http://www.securitytracker.com/id?1021967Broken Link
- http://www.us-cert.gov/cas/techalerts/TA09-132A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2009/0915Vendor Advisory
- http://www.vupen.com/english/advisories/2009/1290Broken Link
- http://www.zerodayinitiative.com/advisories/ZDI-09-019Third Party Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-01Vendor Advisory
FAQ
What is CVE-2009-0556?
CVE-2009-0556 is a vulnerability with a CVSS score of 8.8 (HIGH). Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTe...
How severe is CVE-2009-0556?
CVE-2009-0556 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-0556?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Office Powerpoint, Microsoft Powerpoint.