CVE-2009-0557: Microsoft Office Object Record Corruption Vulnerability
Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Object Record Corruption Vulnerability."
Other sources
Microsoft Office contains an object record corruption vulnerability that allows remote attackers to execute code via a crafted Excel file with a malformed record object.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0557?
CVE-2009-0557 has been rated as critical due to the potential for remote code execution.
How do I fix CVE-2009-0557?
To fix CVE-2009-0557, users should apply the latest security updates provided by Microsoft for the affected Office versions.
What software is affected by CVE-2009-0557?
CVE-2009-0557 affects various versions of Microsoft Office including Office 2000 SP3, Office XP SP3, and Office 2003 SP3 among others.
What types of attacks exploit CVE-2009-0557?
CVE-2009-0557 can be exploited through malicious Excel files that, when opened, can execute arbitrary code.
Is CVE-2009-0557 still a concern for users of outdated Office versions?
Yes, users of outdated Office versions remain vulnerable to CVE-2009-0557 if they have not applied necessary patches or updates.