TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2009-0556

HIGHCISA KEV
8.8

Beschreibung

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Memory Corruption Vulnerability."

CVE Details

CVSS v3.1 Bewertung8.8
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht4/3/2009
Zuletzt geandert4/22/2026
Quellekev
Honeypot-Sichtungen0

CISA KEV

HerstellerMicrosoft
ProduktOffice
SchwachstellennameMicrosoft Office PowerPoint Code Injection Vulnerability
KEV Aufnahmedatum2026-01-07
Behebungsfrist2026-01-28
Ransomware-NutzungUnknown

Betroffene Produkte

microsoft:office_powerpointmicrosoft:powerpoint

Schwachen (CWE)

CWE-94CWE-94

Referenzen

http://osvdb.org/53182(secure@microsoft.com)
http://osvdb.org/53182(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/34572(af854a3a-2127-422b-91ae-364da2661108)
http://www.kb.cert.org/vuls/id/627331(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/34351(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id?1021967(af854a3a-2127-422b-91ae-364da2661108)
http://www.us-cert.gov/cas/techalerts/TA09-132A.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2009/0915(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2009/1290(af854a3a-2127-422b-91ae-364da2661108)
http://www.zerodayinitiative.com/advisories/ZDI-09-019(af854a3a-2127-422b-91ae-364da2661108)

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.