TROYANOSYVIRUS
Volver a CVEs

CVE-2009-0556

HIGHCISA KEV
8.8

Descripcion

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Memory Corruption Vulnerability."

Detalles CVE

Puntuacion CVSS v3.18.8
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioREQUIRED
Publicado4/3/2009
Ultima modificacion4/22/2026
Fuentekev
Avistamientos honeypot0

CISA KEV

VendedorMicrosoft
ProductoOffice
Nombre vulnerabilidadMicrosoft Office PowerPoint Code Injection Vulnerability
Fecha inclusion KEV2026-01-07
Fecha limite remediacion2026-01-28
Uso en ransomwareUnknown

Productos afectados

microsoft:office_powerpointmicrosoft:powerpoint

Debilidades (CWE)

CWE-94CWE-94

Referencias

http://osvdb.org/53182(secure@microsoft.com)
http://osvdb.org/53182(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/34572(af854a3a-2127-422b-91ae-364da2661108)
http://www.kb.cert.org/vuls/id/627331(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/34351(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id?1021967(af854a3a-2127-422b-91ae-364da2661108)
http://www.us-cert.gov/cas/techalerts/TA09-132A.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2009/0915(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2009/1290(af854a3a-2127-422b-91ae-364da2661108)
http://www.zerodayinitiative.com/advisories/ZDI-09-019(af854a3a-2127-422b-91ae-364da2661108)

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.