ZeroHour

CVE-2009-3129

KEVmass

CVE-2009-3129: Memory Corruption RCE in Microsoft Excel via FEATHEADER Record

CISA: Microsoft Excel Featheader Record Memory Corruption Vulnerability

CVSS
EPSS
86%p100
Published
KEV added
AI analysis

Microsoft Office Excel contains a memory corruption flaw in its parsing of the FEATHEADER record in spreadsheet files. An attacker triggers it by getting a user to open a crafted spreadsheet whose FEATHEADER record carries an invalid cbHdrData size value, which corrupts a pointer offset and allows execution of arbitrary code with the privileges of the logged-in user. Anyone running the affected Microsoft Excel versions is exposed, with the highest risk wherever users open spreadsheets arriving by email or from untrusted sources; the available data does not enumerate specific vulnerable versions. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-03, EPSS assigns an 85.7% probability of exploitation within 30 days (100th percentile), and the related public reporting ties this Excel exploit to the first stage of the 'Red October' cyber espionage campaign uncovered by Kaspersky Lab. No public proof-of-concept is cataloged, and ransomware use is unknown.

What to do: Apply Microsoft's Office/Excel security updates per vendor instructions, as required by the CISA KEV catalog, and prioritize an audit for legacy or infrequently patched Office installations that may have missed the 2009 remediation. Until patched, treat unsolicited or externally sourced Excel spreadsheets as untrusted and block or carefully inspect them at email and web gateways. Note that this flaw is associated with espionage-style spearphishing delivery, so also hunt for spreadsheet-opening anomalies in user workstations.

Affected
Microsoft Excel
Estimated exposure
masstens of millions of Microsoft Excel/Office users (Excel ships with Microsoft Office, whose installed base runs to hundreds of millions of desktops, including a… — Estimated from Microsoft Office's enormous installed base and the persistence of legacy, never-upgraded Excel deployments in government, industrial, and offline environments, since exact counts of still-unpatched vulnerable versions are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Office Excel allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset.

CISA Known Exploited Vulnerability
Affected
Microsoft Excel
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Excel
Weakness
CWE-94

In the news