← Vulnerability feed

Vulnerability record · CVE-2009-0224 · published 12 May 2009

CVE-2009-0224: Microsoft compatibility pack word excel powerpoint code injection vulnerability

Microsoft · Compatibility Pack Word Excel Powerpoint

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; PowerPoint Viewer 2003 and 2007 SP1 and SP2; PowerPoint in Microsoft Office 2004 for Mac and 2008 for Mac; Open XML File Format Converter for Mac; Microsoft Works 8.5 and 9.0; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly validate PowerPoint files, which allows remote attackers to execute arbitrary code via multiple crafted BuildList records that include ChartBuild containers, which triggers memory corruption, aka "Memory Corruption Vulnerability."

9.3 CVSS 2.0 High EPSS 30% · top 1.8% CWE-94 · Code injection
9.3CVSS 2.0 base score
30%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; PowerPoint Viewer 2003 and 2007 SP1 and SP2; PowerPoint in Microsoft Office 2004 for Mac and 2008 for Mac; Open XML File Format Converter for Mac; Microsoft Works 8.5 and 9.0; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly validate PowerPoint files, which allows remote attackers to execute arbitrary code via multiple crafted BuildList records that include ChartBuild containers, which triggers memory corruption, aka "Memory Corruption Vulnerability."

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-0224 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2009-0556Microsoft PowerPoint memory corruption via malformed OutlineTextRefAtomMicrosoft PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and PowerPoint in Office 2004 for Mac mishandle an OutlineTextRefAtom with an invalid index value,…KEVEPSS 67%analysed7.8CVE-2010-3333Microsoft Office RTF stack buffer overflow allows code executionA stack-based buffer overflow in Microsoft Office (XP SP3, 2003 SP3, 2007 SP2, 2010, and Mac editions) and the Open XML File Format Converter for Mac…KEVEPSS 89%analysed7.8CVE-2009-3129Microsoft Excel FEATHEADER record memory corruptionMicrosoft Excel and related Office components mishandle a FEATHEADER record whose cbHdrData size element is invalid, corrupting a pointer offset and …KEVEPSS 84%analysed7.8CVE-2009-0557Microsoft Excel malformed record object code executionMicrosoft Excel and related Office components fail to properly handle a malformed record object in a crafted Excel file, allowing code injection. A r…KEVEPSS 53%analysed7.8CVE-2009-0563Microsoft Word stack buffer overflow via crafted document tagA stack-based buffer overflow exists in Microsoft Word and related Office components when parsing a Word document containing a crafted tag with an in…KEVEPSS 63%analysed9.3CVE-2011-1987Microsoft excel memory buffer overflow vulnerabilityArray index error in Microsoft Excel 2003 SP3 and 2007 SP2; Excel in Office 2007 SP2; Excel 2010 Gold and SP1; Excel in Office 2010 Gold and SP1; Off…EPSS 20%9.3CVE-2011-1988Microsoft excel memory buffer overflow vulnerabilityMicrosoft Excel 2003 SP3 and 2007 SP2; Excel in Office 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer S…EPSS 19%9.3CVE-2011-1989Microsoft excel improper input validation vulnerabilityMicrosoft Excel 2003 SP3 and 2007 SP2; Excel in Office 2007 SP2; Excel 2010 Gold and SP1; Excel in Office 2010 Gold and SP1; Office 2004, 2008, and 2…EPSS 21%

Source: NIST National Vulnerability Database (record CVE-2009-0224), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.