← Vulnerability feed

Vulnerability record · CVE-2009-1128 · published 12 May 2009

CVE-2009-1128: Microsoft office powerpoint code injection vulnerability

Microsoft · Office Powerpoint

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to memory corruption, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1129.

9.3 CVSS 2.0 High EPSS 27% · top 2.0% CWE-94 · Code injection
9.3CVSS 2.0 base score
27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to memory corruption, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1129.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-1128 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2009-0556Microsoft PowerPoint memory corruption via malformed OutlineTextRefAtomMicrosoft PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and PowerPoint in Office 2004 for Mac mishandle an OutlineTextRefAtom with an invalid index value,…KEVEPSS 67%analysed9.3CVE-2009-0202Microsoft office powerpoint code injection vulnerabilityArray index error in FL21WIN.DLL in the PowerPoint Freelance Windows 2.1 Translator in Microsoft PowerPoint 2000 and 2002 allows remote attackers to …EPSS 24%9.3CVE-2009-0220Microsoft office powerpoint memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in the PowerPoint 4.0 importer (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 all…EPSS 37%9.3CVE-2009-0221Microsoft office powerpoint vulnerabilityInteger overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a PowerPoint file contain…EPSS 38%9.3CVE-2009-0222Microsoft office powerpoint code injection vulnerabilityMicrosoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that …EPSS 32%9.3CVE-2009-0223Microsoft office powerpoint code injection vulnerabilityMicrosoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that …EPSS 28%9.3CVE-2009-0224Microsoft compatibility pack word excel powerpoint code injection vulnerabilityMicrosoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; PowerPoint Viewer 2003 and 2007 SP1 and SP2; PowerPoint in Microsoft …EPSS 30%9.3CVE-2009-0225Microsoft office powerpoint code injection vulnerabilityMicrosoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 nat…EPSS 31%

Source: NIST National Vulnerability Database (record CVE-2009-1128), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.