CVE-2009-0562

Microsoft Office Web Components - Remote Code Execution via Memory Allocation Corruption

Title source: llm
STIX 2.1

Description

The Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 does not properly allocate memory, which allows remote attackers to execute arbitrary code via unspecified vectors that trigger "system state" corruption, aka "Office Web Components Memory Allocation Vulnerability."

References (4)

Core 4
Core References
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA09-223A.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1022708
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6337

Scores

EPSS 0.2565
EPSS Percentile 97.8%

Details

CWE
CWE-399
Status published
Products (8)
microsoft/isa_server 2004 sp3 (2 CPE variants)
microsoft/isa_server 2006 sp1 (2 CPE variants)
microsoft/office
microsoft/office 2003 sp3
microsoft/office xp sp3
microsoft/office_web_components 2000 sp3
microsoft/office_web_components 2003 sp1 (2 CPE variants)
microsoft/office_web_components xp sp3
Published Aug 12, 2009
Tracked Since Feb 18, 2026