Vulnerability record · CVE-2009-0563 · published 10 June 2009
CVE-2009-0563: Microsoft Word stack buffer overflow via crafted document tag
Microsoft · Office
A stack-based buffer overflow exists in Microsoft Word and related Office components when parsing a Word document containing a crafted tag with an invalid length field. Successful exploitation allows remote code execution in the context of the user who opens the document. The flaw affects multiple Word versions and viewers, making it broadly relevant to document-handling environments.
Description
Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; Microsoft Office Word Viewer 2003 SP3; Microsoft Office Word Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a Word document with a crafted tag containing an invalid length field, aka "Word Buffer Overflow Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe vulnerability is in CISA KEV with a high EPSS score and allows remote code execution via a common attack vector (malicious document), posing an immediate risk to unpatched systems.
What it is
A stack-based buffer overflow exists in Microsoft Word and related Office components when parsing a Word document containing a crafted tag with an invalid length field. Successful exploitation allows remote code execution in the context of the user who opens the document. The flaw affects multiple Word versions and viewers, making it broadly relevant to document-handling environments.
Impact
An attacker can execute arbitrary code with the privileges of the user who opens the malicious document. This can lead to full system compromise, data theft, or installation of malware.
Attack surface
The vulnerability is reached by opening a specially crafted Word document, requiring user interaction (UI:R) and no authentication (PR:N). The CVSS vector indicates local access (AV:L), consistent with opening a file on the target system.
Exploitation
CVE-2009-0563 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-08), indicating active exploitation in the wild. EPSS probability is 0.63081 (99.16th percentile), reflecting a high likelihood of exploitation.
What to do
- Apply the Microsoft security update referenced in MS09-027 immediately.
- Disable or restrict the use of affected Word versions and viewers where patching is not possible.
- Use Microsoft Office File Block policies to prevent opening untrusted Word documents.
- Educate users not to open unexpected or unsolicited Word attachments.
- Consider application whitelisting and endpoint detection to block malicious document execution.
Detection
- Monitor for Word processes spawning child processes such as cmd.exe or powershell.exe.
- Inspect Word documents for malformed tags or invalid length fields using static analysis or sandboxing.
- Review endpoint logs for unusual file writes or network connections originating from WINWORD.EXE.
- Use YARA rules to detect known exploit patterns in Word documents.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2009-0563 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Microsoft Office Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-0563 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-0563), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.