← Vulnerability feed

Vulnerability record · CVE-2009-0556 · published 3 April 2009

CVE-2009-0556: Microsoft PowerPoint memory corruption via malformed OutlineTextRefAtom

Microsoft · Office Powerpoint

Microsoft PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and PowerPoint in Office 2004 for Mac mishandle an OutlineTextRefAtom with an invalid index value, causing memory corruption. Opening a crafted PowerPoint file can let a remote attacker run arbitrary code in the context of the user. The flaw was exploited in the wild in April 2009.

8.8 CVSS 3.1 High CISA KEV since 7 Jan 2026 EPSS 67% · top 0.7% CWE-94 · Code injection
8.8CVSS 3.1 base score, v2 9.3
67%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
37References
16 Jun 2026Last modified by NVD

Description

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Memory Corruption Vulnerability."

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw allows remote code execution, was exploited in the wild, and is in CISA KEV with a near-term remediation deadline.

What it is

Microsoft PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and PowerPoint in Office 2004 for Mac mishandle an OutlineTextRefAtom with an invalid index value, causing memory corruption. Opening a crafted PowerPoint file can let a remote attacker run arbitrary code in the context of the user. The flaw was exploited in the wild in April 2009.

Impact

An attacker who gets a victim to open a malicious PowerPoint file can execute arbitrary code with the victim's privileges, leading to full compromise of confidentiality, integrity, and availability on that host.

Attack surface

Reached by delivering a malicious PowerPoint file to a user, who must open it; the CVSS vector shows network delivery with no privileges required but user interaction required. No authentication is needed on the attacker's side.

Exploitation

Exploitation occurred in the wild in April 2009, and the CVE is listed in CISA KEV with a 2026-01-28 remediation due date. EPSS is 0.67539 (99.274th percentile), indicating high predicted exploitation activity.

What to do

  • Apply the Microsoft security update for MS09-017 (or the vendor's current replacement guidance) to all affected PowerPoint and Office installations.
  • If patching is not possible, follow CISA KEV required action: apply vendor mitigations, follow BOD 22-01 guidance for cloud services, or discontinue use of the affected product.
  • Block or strip PowerPoint attachments at email and web gateways where business use does not require them.
  • Disable or restrict opening of untrusted Office documents via Office Trust Center and Protected View settings.
  • Retire end-of-life versions (PowerPoint 2000, 2002, 2003, Office 2004 for Mac) that no longer receive security fixes.

Detection

  • Hunt for PowerPoint processes (POWERPNT.EXE) spawning child processes such as cmd.exe, powershell.exe, or wscript.exe.
  • Monitor for Office documents written to or executed from temp, download, or email attachment directories.
  • Alert on known exploit file names or hashes associated with Exploit:Win32/Apptom.gen where available.
  • Review endpoint and email logs for PowerPoint files containing malformed OutlineTextRefAtom structures or anomalous OLE streams.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2009-0556 to the Known Exploited Vulnerabilities catalog on 7 January 2026 as "Microsoft Office PowerPoint Code Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 28 January 2026.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://blogs.technet.com/mmpc/archive/2009/04/02/new-0-day-exploits-using-powerpoint-files.aspx Vendor Advisory
http://blogs.technet.com/msrc/archive/2009/04/02/microsoft-security-advisory-969136.aspx Vendor Advisory
http://blogs.technet.com/srd/archive/2009/04/02/investigating-the-new-powerpoint-issue.aspx Vendor Advisory
http://osvdb.org/53182 Broken Link
http://secunia.com/advisories/34572 Vendor Advisory
http://www.kb.cert.org/vuls/id/627331 US Government Resource
http://www.microsoft.com/technet/security/advisory/969136.mspx PatchVendor Advisory
http://www.securityfocus.com/archive/1/503453/100/0/threaded Broken Link
http://www.securityfocus.com/bid/34351 Broken Link
http://www.securitytracker.com/id?1021967 Broken Link
http://www.us-cert.gov/cas/techalerts/TA09-132A.html US Government Resource
http://www.vupen.com/english/advisories/2009/0915 Vendor Advisory
http://www.vupen.com/english/advisories/2009/1290 Broken Link
http://www.zerodayinitiative.com/advisories/ZDI-09-019 Third Party Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-017 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/49632 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6204 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6279 Broken Link
http://blogs.technet.com/mmpc/archive/2009/04/02/new-0-day-exploits-using-powerpoint-files.aspx Vendor Advisory
http://blogs.technet.com/msrc/archive/2009/04/02/microsoft-security-advisory-969136.aspx Vendor Advisory
http://blogs.technet.com/srd/archive/2009/04/02/investigating-the-new-powerpoint-issue.aspx Vendor Advisory
http://osvdb.org/53182 Broken Link
http://secunia.com/advisories/34572 Vendor Advisory
http://www.kb.cert.org/vuls/id/627331 US Government Resource
http://www.microsoft.com/technet/security/advisory/969136.mspx PatchVendor Advisory
http://www.securityfocus.com/archive/1/503453/100/0/threaded Broken Link
http://www.securityfocus.com/bid/34351 Broken Link
http://www.securitytracker.com/id?1021967 Broken Link
http://www.us-cert.gov/cas/techalerts/TA09-132A.html US Government Resource
http://www.vupen.com/english/advisories/2009/0915 Vendor Advisory
http://www.vupen.com/english/advisories/2009/1290 Broken Link
http://www.zerodayinitiative.com/advisories/ZDI-09-019 Third Party Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-017 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/49632 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6204 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6279 Broken Link
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-0556 US Government Resource

Track CVE-2009-0556 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2015-2424Microsoft Office memory corruption via crafted documentCVE-2015-2424 is an out-of-bounds write (CWE-787) in Microsoft PowerPoint and Word that is triggered when a crafted Office document is opened. A remo…KEVEPSS 40%analysed8.8CVE-2007-0671Microsoft Excel remote code execution via malformed fileCVE-2007-0671 is an unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, that allows re…KEVEPSS 43%analysed7.8CVE-2010-2572Microsoft PowerPoint buffer overflow via crafted PowerPoint 95 fileMicrosoft PowerPoint 2002 SP3 and 2003 SP3 contain a buffer overflow when parsing a crafted PowerPoint 95 document. Opening the malicious file can co…KEVEPSS 59%analysed9.3CVE-2015-2503Microsoft access permissions and access controls vulnerabilityMicrosoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2007 SP3, Visio 2007…EPSS 17%9.3CVE-2015-1682Microsoft excel memory buffer overflow vulnerabilityMicrosoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, O…EPSS 19%9.3CVE-2015-0097Microsoft excel vulnerabilityMicrosoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 allow remote attackers to execut…EPSS 41%9.3CVE-2015-0085Microsoft excel vulnerabilityUse-after-free vulnerability in Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, Power…EPSS 19%9.3CVE-2011-3396Microsoft powerpoint vulnerabilityUntrusted search path vulnerability in Microsoft PowerPoint 2007 SP2 and 2010 allows local users to gain privileges via a Trojan horse DLL in the cur…EPSS 18%

Source: NIST National Vulnerability Database (record CVE-2009-0556), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.