CVE-2009-0556
KEVmassCode Injection RCE in Microsoft Office PowerPoint via Malformed File
CISA: Microsoft Office PowerPoint Code Injection Vulnerability
Microsoft Office PowerPoint is affected by a code injection vulnerability (CWE-94) in which a PowerPoint file containing an OutlineTextRefAtom record with an invalid index value corrupts memory when the file is processed. An attacker triggers the flaw by persuading a user to open or preview a crafted PowerPoint document, most plausibly delivered through email attachments or downloaded files. Successful exploitation yields remote code execution in the context of the user who opened the file. CISA lists the affected product simply as 'Microsoft Office' without version bounds; this is a 2009-era PowerPoint flaw, so realistic exposure centers on environments still running unpatched, legacy Office/PowerPoint components. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-07, confirming active exploitation in the wild (ransomware use unknown), and EPSS assigns a 67.5% probability of exploitation within 30 days (99th percentile), while no public proof-of-concept is known.
What to do: Apply mitigations per Microsoft's instructions and applicable BOD 22-01 guidance for cloud services, or discontinue legacy PowerPoint use if mitigations are unavailable. Confirm that all endpoints carry the Office/PowerPoint security updates from 2009 that fixed this flaw, and audit the environment for old Office versions still in use (including on shared or kiosk machines) since in-the-wild exploitation has resumed. As an interim measure, avoid opening unsolicited or untrusted PowerPoint files until patches or mitigations are confirmed in place.
| Microsoft Office (PowerPoint) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an invalid index value that triggers memory corruption.
- Affected
- Microsoft Office
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- Office
- Weakness
- CWE-94