CVE-2009-0563: Microsoft Office Buffer Overflow Vulnerability
Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted tag containing an invalid length field.
Other sources
Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; Microsoft Office Word Viewer 2003 SP3; Microsoft Office Word Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a Word document with a crafted tag containing an invalid length field, aka "Word Buffer Overflow Vulnerability."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0563?
CVE-2009-0563 has a moderate severity rating due to its potential for remote code execution.
How do I fix CVE-2009-0563?
To fix CVE-2009-0563, users should apply the latest security updates from Microsoft for affected Office products.
What versions of Microsoft Office are affected by CVE-2009-0563?
CVE-2009-0563 affects Microsoft Office Word 2002, 2003, 2007, and various Office compatibility packs.
Can CVE-2009-0563 be exploited from emails?
Yes, CVE-2009-0563 can be exploited through malicious Word documents often delivered via email.
What impact can CVE-2009-0563 have on my system?
If exploited, CVE-2009-0563 can allow remote attackers to execute arbitrary code, potentially compromising the system.