ZeroHour
Security Affairspublished ()ingested @securityaffairs1

U.S. CISA adds HPE OneView and Microsoft Office PowerPoint flaws to its Known Exploited Vulnerabilities catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2009-0556CVE-2025-37164

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2009-0556
Code Injection RCE in Microsoft Office PowerPoint via Malformed File

Microsoft Office PowerPoint is affected by a code injection vulnerability (CWE-94) in which a PowerPoint file containing an OutlineTextRefAtom record with an invalid index value corrupts memory when the file is processed. An attacker triggers the flaw by persuading a user to open or preview a crafted PowerPoint document, most plausibly delivered through email attachments or downloaded files. Successful exploitation yields remote code execution in the context of the user who opened the file. CISA lists the affected product simply as 'Microsoft Office' without version bounds; this is a 2009-era PowerPoint flaw, so realistic exposure centers on environments still running unpatched, legacy Office/PowerPoint components. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-07, confirming active exploitation in the wild (ransomware use unknown), and EPSS assigns a 67.5% probability of exploitation within 30 days (99th percentile), while no public proof-of-concept is known.

Do: Apply mitigations per Microsoft's instructions and applicable BOD 22-01 guidance for cloud services, or discontinue legacy PowerPoint use if mitigations are unavailable. Confirm that all endpoints carry the Office/PowerPoint security updates from 2009 that fixed this flaw, and audit the environment for old Office versions still in use (including on shared or kiosk machines) since in-the-wild exploitation has resumed. As an interim measure, avoid opening unsolicited or untrusted PowerPoint files until patches or mitigations are confirmed in place.

68% KEV
  • Microsoft Office (PowerPoint)
mass≈100M+ Office installations in scope; the plausibly exploitable subset is limited to unpatched, legacy PowerPoint installs (unknown)
CVE-2025-37164
Unauthenticated Remote Code Execution in HPE OneView

HPE OneView, HPE's infrastructure management platform, contains a code-injection flaw (CWE-94) that permits unauthenticated remote code execution, with a network-vector, low-complexity CVSS 3.1 score of 9.8 meaning no credentials, privileges, or user interaction are required. An attacker triggers the flaw by sending crafted code-injection input to the OneView appliance over the network, gaining code execution with high impact on the confidentiality, integrity, and availability of the appliance. A compromised OneView instance can serve as a foothold into the HPE server estate it manages, and the RondoDox botnet has already been observed folding this flaw into its exploitation waves. Any organization running an HPE OneView appliance is affected, particularly where the appliance is reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-07, a public Metasploit exploit module is available, and EPSS assigns a 90.2% probability of exploitation within 30 days (100th percentile).

Do: Upgrade OneView to the fixed release specified in the HPE security bulletin for CVE-2025-37164 (exact version numbers are not included in this data), and treat patching as urgent given confirmed in-the-wild exploitation and the public Metasploit module. Until patched, remove unnecessary internet exposure of the OneView appliance and review appliance and network logs for signs of compromise, including possible RondoDox botnet infection. US federal agencies must apply mitigations per vendor instructions and BOD 22-01 guidance, or discontinue use of the product if mitigations are unavailable.

9.890% KEV PoC
  • HPE OneView
large≈ tens of thousands of deployed OneView appliance instances worldwide, with the internet-exposed subset likely in the thousands
Full article392 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds HPE OneView and Microsoft Office PowerPoint flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added HPE OneView and Microsoft Office PowerPoint flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the flaws added to the catalog:

CVE-2009-0556 is a memory corruption flaw in legacy Microsoft PowerPoint that allows attackers to execute arbitrary code via a crafted .ppt file. An invalid index in the OutlineTextRefAtom triggers improper memory handling when the file is opened. Exploited in the wild in April 2009 (Exploit:Win32/Apptom.gen), it affects PowerPoint 2000/2002/2003 and Office 2004 for Mac, enabling full compromise with user privileges.

“Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka “Memory Corruption Vulnerability.”” reads the advisory.

In December, Hewlett Packard Enterprise (HPE) addressed a maximum-severity security vulnerability, tracked as CVE-2025-37164 (CVSS score of 10.0), in OneView Software. An attacker can exploit the flaw to achieve remote code execution.

HPE OneView is an integrated IT management and automation platform by Hewlett Packard Enterprise used to manage, monitor, and automate HPE data center infrastructure.

It provides a single, software-defined interface to control servers, storage, and networking, mainly in HPE environments (e.g., ProLiant servers and Synergy systems).

“A potential security vulnerability has been identified in Hewlett Packard Enterprise OneView Software. This vulnerability could be exploited, allowing a remote unauthenticated user to perform remote code execution.” reads the advisory published by the company.

The flaw impacts all versions through v10.20.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by January 28, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/186672/security/u-s-cisa-adds-hpe-oneview-and-microsoft-office-powerpoint-flaws-to-its-known-exploited-vulnerabilities-catalog.html