CVE-2009-0556
microsoft office powerpoint, microsoft powerpoint
Published 3 Apr 2009 · updated 16 Jun 2026 · Analyzed
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 7 Jan 2026, with a remediation deadline of 28 Jan 2026 for US federal agencies.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Description
Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Memory Corruption Vulnerability."
References
- blogs.technet.com/mmpc/archive/2009/04/02/new-0-day-exploits-using-powerpoint-files.aspx · Vendor Advisory
- blogs.technet.com/msrc/archive/2009/04/02/microsoft-security-advisory-969136.aspx · Vendor Advisory
- blogs.technet.com/srd/archive/2009/04/02/investigating-the-new-powerpoint-issue.aspx · Vendor Advisory
- osvdb.org/53182 · Broken Link
- secunia.com/advisories/34572 · Vendor Advisory
- www.kb.cert.org/vuls/id/627331 · US Government Resource
- www.microsoft.com/technet/security/advisory/969136.mspx · Patch, Vendor Advisory
- www.securityfocus.com/archive/1/503453/100/0/threaded · Broken Link
- www.securityfocus.com/bid/34351 · Broken Link
- www.securitytracker.com/id?1021967 · Broken Link
- www.us-cert.gov/cas/techalerts/TA09-132A.html · US Government Resource
- www.vupen.com/english/advisories/2009/0915 · Vendor Advisory
- www.vupen.com/english/advisories/2009/1290 · Broken Link
- www.zerodayinitiative.com/advisories/ZDI-09-019 · Third Party Advisory
- docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-017 · Vendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/49632 · Third Party Advisory
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6204 · Broken Link
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6279 · Broken Link
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-0556 · US Government Resource