CVE-2009-3129
KEVmassCVE-2009-3129: Memory Corruption RCE in Microsoft Excel via FEATHEADER Record
CISA: Microsoft Excel Featheader Record Memory Corruption Vulnerability
Microsoft Office Excel contains a memory corruption flaw in its parsing of the FEATHEADER record in spreadsheet files. An attacker triggers it by getting a user to open a crafted spreadsheet whose FEATHEADER record carries an invalid cbHdrData size value, which corrupts a pointer offset and allows execution of arbitrary code with the privileges of the logged-in user. Anyone running the affected Microsoft Excel versions is exposed, with the highest risk wherever users open spreadsheets arriving by email or from untrusted sources; the available data does not enumerate specific vulnerable versions. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-03, EPSS assigns an 85.7% probability of exploitation within 30 days (100th percentile), and the related public reporting ties this Excel exploit to the first stage of the 'Red October' cyber espionage campaign uncovered by Kaspersky Lab. No public proof-of-concept is cataloged, and ransomware use is unknown.
What to do: Apply Microsoft's Office/Excel security updates per vendor instructions, as required by the CISA KEV catalog, and prioritize an audit for legacy or infrequently patched Office installations that may have missed the 2009 remediation. Until patched, treat unsolicited or externally sourced Excel spreadsheets as untrusted and block or carefully inspect them at email and web gateways. Note that this flaw is associated with espionage-style spearphishing delivery, so also hunt for spreadsheet-opening anomalies in user workstations.
| Microsoft Excel | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Office Excel allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset.
- Affected
- Microsoft Excel
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- Excel
- Weakness
- CWE-94