← Vulnerability feed

Vulnerability record · CVE-2009-0557 · published 10 June 2009

CVE-2009-0557: Microsoft Excel malformed record object code execution

Microsoft · Office

Microsoft Excel and related Office components fail to properly handle a malformed record object in a crafted Excel file, allowing code injection. A remote attacker can exploit this by convincing a user to open a malicious spreadsheet, leading to arbitrary code execution in the context of the user.

7.8 CVSS 3.1 High CISA KEV since 8 Jun 2022 EPSS 53% · top 1.1% CWE-94 · Code injection
7.8CVSS 3.1 base score, v2 9.3
53%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
5Affected product versions listed by NVD
15References
16 Jun 2026Last modified by NVD

Description

Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Object Record Corruption Vulnerability."

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe vulnerability is actively exploited according to CISA KEV and has a high EPSS score, but requires user interaction and affects older, unsupported software, reducing overall risk.

What it is

Microsoft Excel and related Office components fail to properly handle a malformed record object in a crafted Excel file, allowing code injection. A remote attacker can exploit this by convincing a user to open a malicious spreadsheet, leading to arbitrary code execution in the context of the user.

Impact

An attacker can execute arbitrary code with the privileges of the user who opens the crafted file, potentially leading to full system compromise. This could allow installation of malware, data theft, or further lateral movement.

Attack surface

The vulnerability is reached locally via a crafted Excel file, requiring user interaction to open the file. No authentication is needed, as the attack relies on social engineering to get the user to open the malicious document.

Exploitation

The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. EPSS probability is 0.58551 (99th percentile), suggesting a high likelihood of exploitation attempts.

What to do

  • Apply the patch provided in Microsoft Security Bulletin MS09-021.
  • Disable or restrict the opening of Excel files from untrusted sources.
  • Use Microsoft Office File Block policies to prevent older Excel formats from opening.
  • Educate users about the risks of opening unexpected email attachments or downloaded files.
  • Ensure antivirus and endpoint detection tools are up to date and capable of detecting malicious Excel files.

Detection

  • Monitor for processes spawning from Excel or Office applications that exhibit unusual behavior, such as cmd.exe or powershell.exe.
  • Inspect Excel file metadata and structure for malformed record objects using file analysis tools.
  • Enable and review Office application crash logs for signs of exploitation attempts.
  • Use network monitoring to detect outbound connections from Office processes to suspicious IPs or domains.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2009-0557 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Microsoft Office Object Record Corruption Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-0557 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed8.8CVE-2023-35311Microsoft Outlook security feature bypass via TOCTOU race conditionCVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects …KEVEPSS 16%analysed8.8CVE-2019-1297Microsoft Excel memory handling flaw allows remote code executionCVE-2019-1297 is a remote code execution vulnerability in Microsoft Excel caused by improper handling of objects in memory. An attacker who convinces…KEVEPSS 22%analysed8.8CVE-2019-0541Microsoft MSHTML engine input validation flaw allows remote code executionThe MSHTML engine in Microsoft Office, Internet Explorer and related viewers fails to properly validate input, allowing remote code execution. Becaus…KEVEPSS 53%analysed8.8CVE-2018-0798Microsoft Office Equation Editor memory corruption RCEEquation Editor in Microsoft Office 2007 through 2016 mishandles objects in memory, producing an out-of-bounds write (CWE-787) that can be turned int…KEVEPSS 95%analysed8.8CVE-2015-2424Microsoft Office memory corruption via crafted documentCVE-2015-2424 is an out-of-bounds write (CWE-787) in Microsoft PowerPoint and Word that is triggered when a crafted Office document is opened. A remo…KEVEPSS 40%analysed8.8CVE-2015-1770Microsoft Office uninitialized memory use allows remote code executionMicrosoft Office 2013 SP1 and 2013 RT SP1 mishandle uninitialized memory when parsing a crafted Office document, which can lead to arbitrary code exe…KEVEPSS 35%analysed8.8CVE-2012-1856Microsoft Office MSCOMCTL.OCX TabStrip ActiveX Control Remote Code ExecutionThe TabStrip ActiveX control in MSCOMCTL.OCX fails to properly handle system state, allowing a crafted document or web page to corrupt memory and exe…KEVEPSS 72%analysed

Source: NIST National Vulnerability Database (record CVE-2009-0557), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.