CVE-2009-0561: Buffer Overflow
Integer overflow in Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; and Microsoft Office SharePoint Server 2007 SP1 and SP2 allows remote attackers to execute arbitrary code via an Excel file with a Shared String Table (SST) record with a numeric field that specifies an invalid number of unique strings, which triggers a heap-based buffer overflow, aka "Record Integer Overflow Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0561?
CVE-2009-0561 is rated as a critical severity vulnerability that can lead to remote code execution.
How do I fix CVE-2009-0561?
To fix CVE-2009-0561, users should apply the latest security patches provided by Microsoft for the affected Office products.
What versions are affected by CVE-2009-0561?
CVE-2009-0561 affects multiple versions of Microsoft Excel including Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2007 SP1 and SP2.
What type of attack can exploit CVE-2009-0561?
CVE-2009-0561 can be exploited through specially crafted Excel files that can execute arbitrary code upon opening.
Is CVE-2009-0561 specific to Windows only?
No, CVE-2009-0561 also affects versions of Excel for Mac, including Office 2004 and 2008.