CVE-2009-0563

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jun 10, 2009
Updated: Dec 19, 2024
CWE ID 787

Summary

CVE-2009-0563 is a critical buffer overflow vulnerability affecting multiple Microsoft Office versions, including Word 2002, 2003, and 2007, as well as their Mac counterparts and converters, Word Viewer, and Compatibility Pack. The issue stems from an invalid length field in a crafted tag found in Word documents, enabling remote attackers to execute arbitrary code without user interaction. This vulnerability poses a significant risk, emphasizing the importance of prompt patches for affected systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Office
  • Microsoft Office Compatibility Pack
  • Microsoft Office Word

Affected Vendors

  • Microsoft