Vulnerability record · CVE-2009-0556 · published 3 April 2009
CVE-2009-0556: Microsoft PowerPoint memory corruption via malformed OutlineTextRefAtom
Microsoft · Office Powerpoint
Microsoft PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and PowerPoint in Office 2004 for Mac mishandle an OutlineTextRefAtom with an invalid index value, causing memory corruption. Opening a crafted PowerPoint file can let a remote attacker run arbitrary code in the context of the user. The flaw was exploited in the wild in April 2009.
Description
Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Memory Corruption Vulnerability."
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw allows remote code execution, was exploited in the wild, and is in CISA KEV with a near-term remediation deadline.
What it is
Microsoft PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and PowerPoint in Office 2004 for Mac mishandle an OutlineTextRefAtom with an invalid index value, causing memory corruption. Opening a crafted PowerPoint file can let a remote attacker run arbitrary code in the context of the user. The flaw was exploited in the wild in April 2009.
Impact
An attacker who gets a victim to open a malicious PowerPoint file can execute arbitrary code with the victim's privileges, leading to full compromise of confidentiality, integrity, and availability on that host.
Attack surface
Reached by delivering a malicious PowerPoint file to a user, who must open it; the CVSS vector shows network delivery with no privileges required but user interaction required. No authentication is needed on the attacker's side.
Exploitation
Exploitation occurred in the wild in April 2009, and the CVE is listed in CISA KEV with a 2026-01-28 remediation due date. EPSS is 0.67539 (99.274th percentile), indicating high predicted exploitation activity.
What to do
- Apply the Microsoft security update for MS09-017 (or the vendor's current replacement guidance) to all affected PowerPoint and Office installations.
- If patching is not possible, follow CISA KEV required action: apply vendor mitigations, follow BOD 22-01 guidance for cloud services, or discontinue use of the affected product.
- Block or strip PowerPoint attachments at email and web gateways where business use does not require them.
- Disable or restrict opening of untrusted Office documents via Office Trust Center and Protected View settings.
- Retire end-of-life versions (PowerPoint 2000, 2002, 2003, Office 2004 for Mac) that no longer receive security fixes.
Detection
- Hunt for PowerPoint processes (POWERPNT.EXE) spawning child processes such as cmd.exe, powershell.exe, or wscript.exe.
- Monitor for Office documents written to or executed from temp, download, or email attachment directories.
- Alert on known exploit file names or hashes associated with Exploit:Win32/Apptom.gen where available.
- Review endpoint and email logs for PowerPoint files containing malformed OutlineTextRefAtom structures or anomalous OLE streams.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2009-0556 to the Known Exploited Vulnerabilities catalog on 7 January 2026 as "Microsoft Office PowerPoint Code Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 28 January 2026.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-0556 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-0556), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.