Vulnerability record · CVE-2009-3129 · published 11 November 2009
CVE-2009-3129: Microsoft Excel FEATHEADER record memory corruption
Microsoft · Excel
Microsoft Excel and related Office components mishandle a FEATHEADER record whose cbHdrData size element is invalid, corrupting a pointer offset and writing out of bounds. Opening a crafted spreadsheet can therefore crash or compromise the application. The flaw affects a wide set of Excel 2002/2003/2007, Mac Office, Viewer and Compatibility Pack products.
Description
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset, aka "Excel Featheader Record Memory Corruption Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows remote code execution via a file the user opens, is in CISA KEV with a very high EPSS score and public exploit code, though it requires user interaction and affects legacy products.
What it is
Microsoft Excel and related Office components mishandle a FEATHEADER record whose cbHdrData size element is invalid, corrupting a pointer offset and writing out of bounds. Opening a crafted spreadsheet can therefore crash or compromise the application. The flaw affects a wide set of Excel 2002/2003/2007, Mac Office, Viewer and Compatibility Pack products.
Impact
An attacker who gets a victim to open a malicious spreadsheet can execute arbitrary code in the context of the user running Excel. That typically yields full control of the workstation and its data.
Attack surface
Reached locally through a crafted spreadsheet file opened by the user, so user interaction is required and no authentication is needed. The CVSS vector confirms local access with UI:R and PR:N.
Exploitation
CVE-2009-3129 is listed in CISA KEV (added 2022-03-03) and has an EPSS 30-day probability of 0.857 (99.7th percentile), and a public Exploit-DB entry exists, so exploitation is well established. No ransomware campaign use is documented.
What to do
- Apply the Microsoft MS09-067 updates for all affected Excel, Office, Viewer and Compatibility Pack versions.
- Remove or block unsupported Excel 2002/2003 and Office 2004/2008 for Mac installations that cannot be patched.
- Block or quarantine untrusted spreadsheet attachments at email and web gateways.
- Disable or restrict opening of legacy .xls files from external sources where business need allows.
- Run Office/Excel with reduced privileges and enable Protected View for files from the internet.
Detection
- Monitor for Excel processes spawning child processes such as cmd.exe, powershell.exe or wscript.exe.
- Alert on Excel crashes or abnormal terminations tied to recently opened spreadsheet files.
- Scan email and file shares for .xls files containing malformed FEATHEADER records or unusually sized cbHdrData fields.
- Correlate endpoint file-open events for spreadsheets with subsequent suspicious process or network activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2009-3129 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Microsoft Excel Featheader Record Memory Corruption Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-3129 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-3129), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.