LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2009-0557: Microsoft Office Object Record Corruption Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 8, 2022
CVSS 7.8 · High⚠ Actively exploited (CISA KEV)
7.8
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 22, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2009-0557 to its Known Exploited Vulnerabilities catalog on Jun 8, 2022, with a federal patch deadline of Jun 22, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Object Record Corruption Vulnerability."

CVE-2009-0557 is an object record corruption vulnerability in Microsoft Office that can let a remote attacker run code if a user opens a crafted Excel file containing a malformed record object. It matters because Office documents are routinely exchanged by email and file share; a successful exploit can give the attacker the same rights as the signed-in user on the workstation.

Public detail is limited to the CISA summary and the assigned weakness (CWE-94). Confirm exact product editions, fixed builds, and any additional attack vectors against the vendor advisory before acting.

How it works

The flaw belongs to the code-injection class (CWE-94). Microsoft Office fails to handle a malformed object record inside an Excel file correctly. When the application parses that record, memory corruption can occur and attacker-controlled data may be treated as executable code.

An attacker typically delivers the malicious workbook by email, web download, or shared folder and relies on the user to open it. No further user interaction beyond opening the file is described in the public summary. Specifics of the record layout or exact corruption path are not provided here; treat any claimed exploit details as unconfirmed unless they appear in the vendor advisory.

Am I affected? How to find it in your systems

Microsoft Office is commonly installed on Windows endpoints used by knowledge workers, finance teams, and anyone who receives spreadsheets. Inventory every workstation and terminal server that has Excel or the full Office suite.

Telemetry signs of exploitation are generic for Office memory-corruption bugs: sudden Excel crashes followed by anomalous process creation or outbound traffic. Confirm any indicators against the vendor advisory and your own threat-intelligence sources.

How to remediate

Patch first. Apply the Microsoft security update that addresses CVE-2009-0557 exactly as directed in the vendor advisory (CISA required action: apply updates per vendor instructions). After installation, verify the Office build number matches the fixed release.

If you can't patch immediately

Reduce risk with compensating controls until the update can be installed.

If your data may have been exposed

Actively exploited Office vulnerabilities have historically led to credential theft, lateral movement, and data exfiltration. Known ransomware use of this CVE is not documented, but any successful code execution still warrants a full incident-response check of the affected host. If you suspect compromise, isolate the system, preserve memory and disk evidence, and hunt for persistence. You can also run a free exposure scan of your email address to see whether it appears in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Office
WeaknessCWE-94
CVSS base score7.8 (High)
CVSS vectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
PublishedJun 10, 2009
Added to CISA KEVJun 8, 2022
Federal patch deadlineJun 22, 2022
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities