CVE-2009-0563
published 2009-06-10CVE-2009-0563: Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format…
PriorityP180high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-06-22
Exploited in the wild
EPSS
63.08%
99.1th percentile
Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; Microsoft Office Word Viewer 2003 SP3; Microsoft Office Word Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a Word document with a crafted tag containing an invalid length field, aka "Word Buffer Overflow Vulnerability."
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office_compatibility_pack | — | — |
| microsoft | office_word_viewer | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger vector is a Word document (.doc) with a crafted tag containing an invalid length field, delivered as a remote file to exploit a stack-based buffer overflow in Word's tag parsing logic. ↗
- →The vulnerability is a stack-based buffer overflow, so detection should focus on stack-pivot/shellcode patterns triggered during Word document parsing (e.g., abnormal stack pointer manipulation after tag length processing). ↗
- →Scope detection to all affected Word-rendering surfaces: Word 2002/2003/2007, Word Viewer 2003, Office for Mac 2004/2008, Open XML File Format Converter for Mac, and Office Compatibility Pack for Word/Excel/PowerPoint 2007 — any of these processes opening a malicious .doc should be monitored. ↗
- ·Exploitation requires the victim to open a specially crafted Word document; the attack surface is remote/user-assisted, not network-reachable without user interaction. ↗
- ·The vulnerability affects a wide range of Word versions and platforms (Windows and Mac); detection/patching scope must cover all listed product versions, including the Open XML File Format Converter for Mac. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f5c7-c9q4-9h6j: Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File F
ghsa_unreviewed·2022-05-02
CVE-2009-0563 [HIGH] CWE-119 GHSA-f5c7-c9q4-9h6j: Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File F
Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; Microsoft Office Word Viewer 2003 SP3; Microsoft Office Word Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a Word document with a crafted tag containing an invalid length field, aka "Word Buffer Overflow Vulnerability."
VulnCheck
Microsoft Office Buffer Overflow Vulnerability
vulncheck·2009·CVSS 7.8
CVE-2009-0563 [HIGH] CWE-119 Microsoft Office Buffer Overflow Vulnerability
Microsoft Office Buffer Overflow Vulnerability
Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted tag containing an invalid length field.
Affected: Microsoft Office
Required Action: Apply updates per vendor instructions.
Exploitation References: https://securelist.com/new-uyghur-and-tibetan-themed-attacks-using-pdf-exploits/35465/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-06-22
CISA
Microsoft Office Buffer Overflow Vulnerability
cisa·2022-06-08·CVSS 7.8
CVE-2009-0563 [HIGH] CWE-119 Microsoft Office Buffer Overflow Vulnerability
Vulnerability: Microsoft Office Buffer Overflow Vulnerability
Affected: Microsoft Office
Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted tag containing an invalid length field.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2009-0563
Remediation Due Date: 2022-06-22
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/54959http://www.securityfocus.com/archive/1/504204/100/0/threadedhttp://www.securityfocus.com/bid/35188http://www.securitytracker.com/id?1022356http://www.us-cert.gov/cas/techalerts/TA09-160A.htmlhttp://www.vupen.com/english/advisories/2009/1546http://www.zerodayinitiative.com/advisories/ZDI-09-035https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-027https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6133http://osvdb.org/54959http://www.securityfocus.com/archive/1/504204/100/0/threadedhttp://www.securityfocus.com/bid/35188http://www.securitytracker.com/id?1022356http://www.us-cert.gov/cas/techalerts/TA09-160A.htmlhttp://www.vupen.com/english/advisories/2009/1546http://www.zerodayinitiative.com/advisories/ZDI-09-035https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-027https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6133https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-0563
2009-06-10
Published
2022-06-08
Added to CISA KEV
Exploited in the wild