CVE-2009-0561

EXPLOITED

Microsoft Office Excel - Remote Code Execution via Shared String Table Record Integer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2009-0561 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

Integer overflow in Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; and Microsoft Office SharePoint Server 2007 SP1 and SP2 allows remote attackers to execute arbitrary code via an Excel file with a Shared String Table (SST) record with a numeric field that specifies an invalid number of unique strings, which triggers a heap-based buffer overflow, aka "Record Integer Overflow Vulnerability."

References (10)

Core 10
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1540
Vendor Advisory x_refsource_misc
http://secunia.com/secunia_research/2009-12/
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/504190/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_idefense
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=805
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1022351
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5925
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA09-160A.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/54957
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/35245

Scores

EPSS 0.3690
EPSS Percentile 98.4%

Details

VulnCheck KEV 2012-10-18
CWE
CWE-189
Status published
Products (11)
microsoft/office 2004
microsoft/office 2008
microsoft/office xp sp3
microsoft/office_compatibility_pack_for_word_excel_ppt_2007 (2 CPE variants)
microsoft/office_excel 2000 sp3
microsoft/office_excel 2003 sp3
microsoft/office_excel 2007 sp1 (2 CPE variants)
microsoft/office_excel_viewer
microsoft/office_excel_viewer 2003 sp3
microsoft/office_sharepoint_server 2007 sp1 (4 CPE variants)
... and 1 more
Published Jun 10, 2009
Tracked Since Feb 18, 2026