ZeroHour

CVE-2009-0563

KEVmass

Buffer Overflow RCE in Microsoft Office via Crafted Word Document

CISA: Microsoft Office Buffer Overflow Vulnerability

CVSS
EPSS
63%p99
Published
KEV added
AI analysis

CVE-2009-0563 is a buffer overflow (CWE-119) in Microsoft Office in which a Word document containing a crafted tag with an invalid length field overflows a buffer when the document is parsed. An attacker triggers the flaw by persuading a user to open a maliciously crafted Word file, typically delivered via email or a download. Successful exploitation yields remote code execution running in the context of the user who opened the document, allowing the attacker to install or run software, or view and change data. Any user of an affected Microsoft Office release is exposed; the CISA catalog lists the affected product simply as Microsoft Office. Exploitation is confirmed in the wild: CISA added the CVE to the KEV catalog on 2022-06-08, EPSS assigns a 63.1% probability of exploitation within 30 days, and the related headlines describe APT backdoor campaigns against Mac users consistent with targeted use of this flaw.

What to do: Apply Microsoft security updates per vendor instructions, and upgrade or fully patch legacy Office installations that no longer receive updates, verifying that no endpoints (including Mac systems, given reported APT activity) remain on unpatched versions. Treat unsolicited Word documents as untrusted and monitor for suspicious processes spawned by Office when documents are opened. Because this flaw is KEV-listed with known in-the-wild exploitation, prioritize patching and hunt for document-opening activity consistent with targeted attacks.

Affected
Microsoft Office
Estimated exposure
mass≈100M+ users (Office's global install base; remaining unpatched legacy installs plausibly in the millions) — Microsoft Office is deployed on hundreds of millions of seats worldwide, so even a small fraction of systems still running unpatched 2009-era versions plausibly exceeds one million users or devices.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted tag containing an invalid length field.

CISA Known Exploited Vulnerability
Affected
Microsoft Office
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Office
Weakness
CWE-119

In the news