CVE-2009-0259

EXPLOITED IN THE WILD

OpenOffice.org 1.1.2-1.1.5 - Denial of Service and Possible Remote Code Execution via Crafted Word File

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2009-0259 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit from researchers including securfrog.

AI-analyzed exploit summary The provided entry references an external download for a Wordpad .doc file PoC but contains no actual exploit code or technical details. It relies on an off-site RAR file, which is a common tactic for suspicious or malicious repositories.

Description

The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008, as demonstrated by 2008-crash.doc.rar, and a similar issue to CVE-2008-4841.

Exploits (1)

exploitdb SUSPICIOUS VERIFIED
by securfrog · textdoswindows
https://www.exploit-db.com/exploits/6560

The provided entry references an external download for a Wordpad .doc file PoC but contains no actual exploit code or technical details. It relies on an off-site RAR file, which is a common tactic for suspicious or malicious repositories.

Classification
Suspicious 90%
Attack Type
Dos
Complexity
Theoretical
Reliability
Theoretical
Target: Microsoft Windows Wordpad
No auth needed
Prerequisites: Access to the external download link
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/48213
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6560
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/33383
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/01/21/9

Scores

EPSS 0.1660
EPSS Percentile 95.1%

Details

VulnCheck KEV 2009-01-21
InTheWild.io 2017-09-29
CWE
CWE-399
Status published
Products (4)
openoffice/openoffice.org 1.1.2
openoffice/openoffice.org 1.1.3
openoffice/openoffice.org 1.1.4
openoffice/openoffice.org 1.1.5
Published Jan 22, 2009
Tracked Since Feb 18, 2026