CVE-2009-0563
KEVmassBuffer Overflow RCE in Microsoft Office via Crafted Word Document
CISA: Microsoft Office Buffer Overflow Vulnerability
CVE-2009-0563 is a buffer overflow (CWE-119) in Microsoft Office in which a Word document containing a crafted tag with an invalid length field overflows a buffer when the document is parsed. An attacker triggers the flaw by persuading a user to open a maliciously crafted Word file, typically delivered via email or a download. Successful exploitation yields remote code execution running in the context of the user who opened the document, allowing the attacker to install or run software, or view and change data. Any user of an affected Microsoft Office release is exposed; the CISA catalog lists the affected product simply as Microsoft Office. Exploitation is confirmed in the wild: CISA added the CVE to the KEV catalog on 2022-06-08, EPSS assigns a 63.1% probability of exploitation within 30 days, and the related headlines describe APT backdoor campaigns against Mac users consistent with targeted use of this flaw.
What to do: Apply Microsoft security updates per vendor instructions, and upgrade or fully patch legacy Office installations that no longer receive updates, verifying that no endpoints (including Mac systems, given reported APT activity) remain on unpatched versions. Treat unsolicited Word documents as untrusted and monitor for suspicious processes spawned by Office when documents are opened. Because this flaw is KEV-listed with known in-the-wild exploitation, prioritize patching and hunt for document-opening activity consistent with targeted attacks.
| Microsoft Office | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted tag containing an invalid length field.
- Affected
- Microsoft Office
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- Office
- Weakness
- CWE-119