CVE-2009-0556
published 2009-04-03CVE-2009-0556: Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary…
PriorityP184high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-01-28
Exploited in the wild
EPSS
67.54%
99.2th percentile
Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Memory Corruption Vulnerability."
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | office_powerpoint | — | — |
| microsoft | powerpoint | — | — |
| microsoft | powerpoint | — | — |
| microsoft | powerpoint | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →A Snort rule was released on April 10th, 2009 specifically targeting CVE-2009-0556 PowerPoint memory corruption via OutlineTextRefAtom with an invalid index value. ↗
- →The vulnerability is triggered via a malicious PowerPoint file containing an OutlineTextRefAtom record with an invalid index value, leading to memory corruption. Detection should focus on parsing OutlineTextRefAtom records in PPT files for out-of-bounds index values. ↗
- ·Affected products are Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac only — later versions are not affected by this specific vulnerability. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w25v-2mf8-86hr: Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbi
ghsa_unreviewed·2022-05-02
CVE-2009-0556 [HIGH] CWE-94 GHSA-w25v-2mf8-86hr: Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbi
Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Memory Corruption Vulnerability."
VulnCheck
Microsoft Office PowerPoint Code Injection Vulnerability
vulncheck·2009·CVSS 8.8
CVE-2009-0556 [HIGH] CWE-94 Microsoft Office PowerPoint Code Injection Vulnerability
Microsoft Office PowerPoint Code Injection Vulnerability
Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an invalid index value that triggers memory corruption.
Affected: Microsoft Office
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://www.cve.org/CVERecord?id=CVE-2009-0556; https://learn.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-017; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.recordedfuture.com/blog/january-2026
CISA
Microsoft Office PowerPoint Code Injection Vulnerability
cisa·2026-01-07·CVSS 8.8
CVE-2009-0556 [HIGH] CWE-94 Microsoft Office PowerPoint Code Injection Vulnerability
Vulnerability: Microsoft Office PowerPoint Code Injection Vulnerability
Affected: Microsoft Office
Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an invalid index value that triggers memory corruption.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-017 ; https://nvd.nist.gov/vuln/detail/CVE-2009-0556
Remediation Due Date: 2026-01-28
No detection rules found.
No public exploits indexed.
Recorded Future
January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
blogs_recorded_future·2026-02-24·CVSS 7.8
[HIGH] January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
## January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
January 2026 saw a modest 5% increase in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 23 vulnerabilities requiring immediate remediation, up from 22 in December 2025. Noteworthy trends last month included Russian state-sponsored exploitation of a Microsoft Office zero-day and critical authentication bypass flaws affecting enterprise infrastructure.
What security teams need to know:
APT28's Operation Neusploit: Russian state-sponsored actors exploited CVE-2026-21509 (Microsoft Office) via weaponized RTF files, delivering MiniDoor, PixyNetLoader, and Covenant Grunt implants
Microsoft and SmarterTools lead concerns: These vendors accounted
Talos
Rule release for today - April 10th 2009
blogs_talos·2009-04-10·CVSS 8.8
CVE-2009-0556 [HIGH] Rule release for today - April 10th 2009
# Rule release for today - April 10th 2009
By
Nigel Houghton
Friday, April 10, 2009 17:10
Rule for Powerpoint memory corruption bug, CVE-2009-0556, extra rule for MS08-068 and Conficker detection update.
More details here: http://www.snort.org/vrt/advisories/vrt-rules-2009-04-10.html
##### Share this post
Talos
Rule release for today - April 10th 2009
blogs_talos·2009-04-10·CVSS 8.8
CVE-2009-0556 [HIGH] Rule release for today - April 10th 2009
## Rule release for today - April 10th 2009
Rule for Powerpoint memory corruption bug, CVE-2009-0556, extra rule for MS08-068 and Conficker detection update. More details here: http://www.snort.org/vrt/advisories/vrt-rules-2009-04-10.html
Recorded Future
January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
blogs_recorded_future·CVSS 4.9
[MEDIUM] January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
# January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
January 2026 saw a modest 5% increase in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 23 vulnerabilities requiring immediate remediation, up from 22 in December 2025. Noteworthy trends last month included Russian state-sponsored exploitation of a Microsoft Office zero-day and critical authentication bypass flaws affecting enterprise infrastructure.
What security teams need to know:
- APT28's Operation Neusploit: Russian state-sponsored actors exploited CVE-2026-21509 (Microsoft Office) via weaponized RTF files, delivering MiniDoor, PixyNetLoader, and Covenant Grunt implants
- Microsoft and SmarterTools lead concerns: These vendors accounte
http://blogs.technet.com/mmpc/archive/2009/04/02/new-0-day-exploits-using-powerpoint-files.aspxhttp://blogs.technet.com/msrc/archive/2009/04/02/microsoft-security-advisory-969136.aspxhttp://blogs.technet.com/srd/archive/2009/04/02/investigating-the-new-powerpoint-issue.aspxhttp://osvdb.org/53182http://secunia.com/advisories/34572http://www.kb.cert.org/vuls/id/627331http://www.microsoft.com/technet/security/advisory/969136.mspxhttp://www.securityfocus.com/archive/1/503453/100/0/threadedhttp://www.securityfocus.com/bid/34351http://www.securitytracker.com/id?1021967http://www.us-cert.gov/cas/techalerts/TA09-132A.htmlhttp://www.vupen.com/english/advisories/2009/0915http://www.vupen.com/english/advisories/2009/1290http://www.zerodayinitiative.com/advisories/ZDI-09-019https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-017https://exchange.xforce.ibmcloud.com/vulnerabilities/49632https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6204https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6279http://blogs.technet.com/mmpc/archive/2009/04/02/new-0-day-exploits-using-powerpoint-files.aspxhttp://blogs.technet.com/msrc/archive/2009/04/02/microsoft-security-advisory-969136.aspxhttp://blogs.technet.com/srd/archive/2009/04/02/investigating-the-new-powerpoint-issue.aspxhttp://osvdb.org/53182http://secunia.com/advisories/34572http://www.kb.cert.org/vuls/id/627331http://www.microsoft.com/technet/security/advisory/969136.mspxhttp://www.securityfocus.com/archive/1/503453/100/0/threadedhttp://www.securityfocus.com/bid/34351http://www.securitytracker.com/id?1021967http://www.us-cert.gov/cas/techalerts/TA09-132A.htmlhttp://www.vupen.com/english/advisories/2009/0915http://www.vupen.com/english/advisories/2009/1290http://www.zerodayinitiative.com/advisories/ZDI-09-019https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-017https://exchange.xforce.ibmcloud.com/vulnerabilities/49632https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6204https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6279https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-0556
2009-04-03
Published
2026-01-07
Added to CISA KEV
Exploited in the wild