CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2009-0556 | Code Injection RCE in Microsoft Office PowerPoint via Malformed File Microsoft Office PowerPoint is affected by a code injection vulnerability (CWE-94) in which a PowerPoint file containing an OutlineTextRefAtom record with an invalid index value corrupts memory when the file is processed. An attacker triggers the flaw by persuading a user to open or preview a crafted PowerPoint document, most plausibly delivered through email attachments or downloaded files. Successful exploitation yields remote code execution in the context of the user who opened the file. CISA lists the affected product simply as 'Microsoft Office' without version bounds; this is a 2009-era PowerPoint flaw, so realistic exposure centers on environments still running unpatched, legacy Office/PowerPoint components. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-07, confirming active exploitation in the wild (ransomware use unknown), and EPSS assigns a 67.5% probability of exploitation within 30 days (99th percentile), while no public proof-of-concept is known. Do: Apply mitigations per Microsoft's instructions and applicable BOD 22-01 guidance for cloud services, or discontinue legacy PowerPoint use if mitigations are unavailable. Confirm that all endpoints carry the Office/PowerPoint security updates from 2009 that fixed this flaw, and audit the environment for old Office versions still in use (including on shared or kiosk machines) since in-the-wild exploitation has resumed. As an interim measure, avoid opening unsolicited or untrusted PowerPoint files until patches or mitigations are confirmed in place. | — | 68% | KEV |
| mass≈100M+ Office installations in scope; the plausibly exploitable subset is limited to unpatched, legacy PowerPoint installs (unknown) | |
| CVE-2025-37164 | Unauthenticated Remote Code Execution in HPE OneView HPE OneView, HPE's infrastructure management platform, contains a code-injection flaw (CWE-94) that permits unauthenticated remote code execution, with a network-vector, low-complexity CVSS 3.1 score of 9.8 meaning no credentials, privileges, or user interaction are required. An attacker triggers the flaw by sending crafted code-injection input to the OneView appliance over the network, gaining code execution with high impact on the confidentiality, integrity, and availability of the appliance. A compromised OneView instance can serve as a foothold into the HPE server estate it manages, and the RondoDox botnet has already been observed folding this flaw into its exploitation waves. Any organization running an HPE OneView appliance is affected, particularly where the appliance is reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-07, a public Metasploit exploit module is available, and EPSS assigns a 90.2% probability of exploitation within 30 days (100th percentile). Do: Upgrade OneView to the fixed release specified in the HPE security bulletin for CVE-2025-37164 (exact version numbers are not included in this data), and treat patching as urgent given confirmed in-the-wild exploitation and the public Metasploit module. Until patched, remove unnecessary internet exposure of the OneView appliance and review appliance and network logs for signs of compromise, including possible RondoDox botnet infection. US federal agencies must apply mitigations per vendor instructions and BOD 22-01 guidance, or discontinue use of the product if mitigations are unavailable. | 9.8 | 90% | KEV PoC |
| large≈ tens of thousands of deployed OneView appliance instances worldwide, with the internet-exposed subset likely in the thousands |
Full article474 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJan 08, 2026Vulnerability / KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added two security flaws impacting Microsoft Office and Hewlett Packard Enterprise (HPE) OneView to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerabilities are listed below -
- CVE-2009-0556 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office PowerPoint that allows remote attackers to execute arbitrary code by means of memory corruption
- CVE-2025-37164 (CVSS score: 10.0) - A code injection vulnerability in HPW OneView that allows a remote unauthenticated user to perform remote code execution
Details of CVE-2025-37164 emerged last month when HPE said the vulnerability impacts all versions of the software prior to version 11.00. The company also made available hotfixes for OneView versions 5.20 through 10.
The scope and source of the attacks targeting the two flaws is presently unclear, and there appear to be no public reports referencing their exploitation in the wild. However, a report from eSentire on December 23, 2025, revealed the release of a detailed proof-of-concept (PoC) exploit for CVE-2025-37164.
"Public availability of PoC exploit code significantly increases the risk to organizations running affected versions of the application," eSentire said. "As the vulnerability impacts all versions prior to 11.0, organizations are strongly advised to apply the required updates to mitigate the potential risk of exploitation."
Pursuant to Binding Operational Directive (BOD) 22-01, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary fixes by January 28, 2026, to secure their networks against active threats.
HPE OneView Flaw Exploited by RondoDox Botnet
In a report published January 15, 2026, Check Point said it identified an active, large-scale exploitation campaign targeting CVE-2025-37164 that delivers the RondoDox botnet, adding it reported the activity to CISA on January 7, 2026, prompting its inclusion in the KEV catalog that same day.
The exploitation effort involved more than 40,000 attack attempts between 05:45 and 09:20 UTC on January 7, 2026, signaling a dramatic escalation. The attempts are assessed to be automated, botnet-driven exploitation.
"The majority of observed activity originated from a single Dutch IP address that has been widely reported online as suspicious," Check Point said. "The campaign impacted organizations across multiple sectors, with the highest concentration of activity observed against government organizations, followed by the financial services and industrial manufacturing sectors."
The U.S. experienced the highest volume of attacks, followed by Australia, France, Germany, and Austria. The findings illustrate the Linux-based botnet is actively adding newly disclosed vulnerabilities to its exploit arsenal to target unpatched systems and expand its reach.
(The story was updated after publication on January 16, 2026, to include details of exploitation activity related to CVE-2025-37164.)
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/01/cisa-flags-microsoft-office-and-hpe.html