ZeroHour

CVE-2009-0556

KEVmass

Code Injection RCE in Microsoft Office PowerPoint via Malformed File

CISA: Microsoft Office PowerPoint Code Injection Vulnerability

CVSS
EPSS
68%p99
Published
KEV added
AI analysis

Microsoft Office PowerPoint is affected by a code injection vulnerability (CWE-94) in which a PowerPoint file containing an OutlineTextRefAtom record with an invalid index value corrupts memory when the file is processed. An attacker triggers the flaw by persuading a user to open or preview a crafted PowerPoint document, most plausibly delivered through email attachments or downloaded files. Successful exploitation yields remote code execution in the context of the user who opened the file. CISA lists the affected product simply as 'Microsoft Office' without version bounds; this is a 2009-era PowerPoint flaw, so realistic exposure centers on environments still running unpatched, legacy Office/PowerPoint components. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-07, confirming active exploitation in the wild (ransomware use unknown), and EPSS assigns a 67.5% probability of exploitation within 30 days (99th percentile), while no public proof-of-concept is known.

What to do: Apply mitigations per Microsoft's instructions and applicable BOD 22-01 guidance for cloud services, or discontinue legacy PowerPoint use if mitigations are unavailable. Confirm that all endpoints carry the Office/PowerPoint security updates from 2009 that fixed this flaw, and audit the environment for old Office versions still in use (including on shared or kiosk machines) since in-the-wild exploitation has resumed. As an interim measure, avoid opening unsolicited or untrusted PowerPoint files until patches or mitigations are confirmed in place.

Affected
Microsoft Office (PowerPoint)
Estimated exposure
mass≈100M+ Office installations in scope; the plausibly exploitable subset is limited to unpatched, legacy PowerPoint installs (unknown) — Estimate is based on the ubiquity of Microsoft Office across hundreds of millions of enterprise and consumer endpoints; because CISA lists 'Microsoft Office' with no version bounds and the flaw is from 2009, the practically vulnerable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an invalid index value that triggers memory corruption.

CISA Known Exploited Vulnerability
Affected
Microsoft Office
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Office
Weakness
CWE-94

In the news