cbcvebase.
CVE-2009-0563
published 2009-06-10

CVE-2009-0563: Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format…

PriorityP180high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-06-22
Exploited in the wild
EPSS
63.08%
99.1th percentile
Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; Microsoft Office Word Viewer 2003 SP3; Microsoft Office Word Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a Word document with a crafted tag containing an invalid length field, aka "Word Buffer Overflow Vulnerability."

Affected

8 ranges
VendorProductVersion rangeFixed in
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice_compatibility_pack
microsoftoffice_word_viewer

Detection & IOCsextracted from sources · hover to see the quote

  • Trigger vector is a Word document (.doc) with a crafted tag containing an invalid length field, delivered as a remote file to exploit a stack-based buffer overflow in Word's tag parsing logic.
  • The vulnerability is a stack-based buffer overflow, so detection should focus on stack-pivot/shellcode patterns triggered during Word document parsing (e.g., abnormal stack pointer manipulation after tag length processing).
  • Scope detection to all affected Word-rendering surfaces: Word 2002/2003/2007, Word Viewer 2003, Office for Mac 2004/2008, Open XML File Format Converter for Mac, and Office Compatibility Pack for Word/Excel/PowerPoint 2007 — any of these processes opening a malicious .doc should be monitored.
  • ·Exploitation requires the victim to open a specially crafted Word document; the attack surface is remote/user-assisted, not network-reachable without user interaction.
  • ·The vulnerability affects a wide range of Word versions and platforms (Windows and Mac); detection/patching scope must cover all listed product versions, including the Open XML File Format Converter for Mac.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.