Vulnerability record · CVE-2009-0557 · published 10 June 2009
CVE-2009-0557: Microsoft Excel malformed record object code execution
Microsoft · Office
Microsoft Excel and related Office components fail to properly handle a malformed record object in a crafted Excel file, allowing code injection. A remote attacker can exploit this by convincing a user to open a malicious spreadsheet, leading to arbitrary code execution in the context of the user.
Description
Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Object Record Corruption Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe vulnerability is actively exploited according to CISA KEV and has a high EPSS score, but requires user interaction and affects older, unsupported software, reducing overall risk.
What it is
Microsoft Excel and related Office components fail to properly handle a malformed record object in a crafted Excel file, allowing code injection. A remote attacker can exploit this by convincing a user to open a malicious spreadsheet, leading to arbitrary code execution in the context of the user.
Impact
An attacker can execute arbitrary code with the privileges of the user who opens the crafted file, potentially leading to full system compromise. This could allow installation of malware, data theft, or further lateral movement.
Attack surface
The vulnerability is reached locally via a crafted Excel file, requiring user interaction to open the file. No authentication is needed, as the attack relies on social engineering to get the user to open the malicious document.
Exploitation
The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. EPSS probability is 0.58551 (99th percentile), suggesting a high likelihood of exploitation attempts.
What to do
- Apply the patch provided in Microsoft Security Bulletin MS09-021.
- Disable or restrict the opening of Excel files from untrusted sources.
- Use Microsoft Office File Block policies to prevent older Excel formats from opening.
- Educate users about the risks of opening unexpected email attachments or downloaded files.
- Ensure antivirus and endpoint detection tools are up to date and capable of detecting malicious Excel files.
Detection
- Monitor for processes spawning from Excel or Office applications that exhibit unusual behavior, such as cmd.exe or powershell.exe.
- Inspect Excel file metadata and structure for malformed record objects using file analysis tools.
- Enable and review Office application crash logs for signs of exploitation attempts.
- Use network monitoring to detect outbound connections from Office processes to suspicious IPs or domains.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2009-0557 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Microsoft Office Object Record Corruption Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-0557 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-0557), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.