LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2009-0556: Microsoft Office PowerPoint Code Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jan 7, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jan 28, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2009-0556 to its Known Exploited Vulnerabilities catalog on Jan 7, 2026, with a federal patch deadline of Jan 28, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an invalid index…

Microsoft Office PowerPoint contains a code injection vulnerability tracked as CVE-2009-0556. Remote attackers can execute arbitrary code by delivering a specially crafted PowerPoint file. This matters for IT and security teams because untrusted presentation files are commonly exchanged via email and file shares, creating a direct path for initial access and subsequent system compromise.

How it works

The weakness is classified under CWE-94, improper control of generation of code. An attacker crafts a PowerPoint file containing an OutlineTextRefAtom structure with an invalid index value.

When the application processes this malformed structure, memory corruption occurs. The corrupted state allows the attacker to influence code execution and run arbitrary commands in the context of the affected process.

Am I affected? How to find it in your systems

This issue affects Microsoft Office installations that include PowerPoint. Inventory all workstations, servers, and virtual desktops that run Microsoft Office applications and handle .ppt or .pptx files.

How to remediate

Apply the vendor update named in the advisory as the primary remediation step. Follow CISA guidance to apply mitigations per vendor instructions or discontinue use of the product if mitigations cannot be implemented.

If you can't patch immediately

Until the vendor update can be applied, implement compensating controls to reduce exposure.

If your data may have been exposed

Actively exploited vulnerabilities in this class can lead to breaches. You can run a free exposure scan of your email addresses to check against known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Office
WeaknessCWE-94
Added to CISA KEVJan 7, 2026
Federal patch deadlineJan 28, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities