CVE-2009-0562
Microsoft Office Web Components - Remote Code Execution via Memory Allocation Corruption
Title source: llmDescription
The Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 does not properly allocate memory, which allows remote attackers to execute arbitrary code via unspecified vectors that trigger "system state" corruption, aka "Office Web Components Memory Allocation Vulnerability."
References (4)
Core 4
Core References
US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA09-223A.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1022708
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6337
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-043
Scores
EPSS
0.2565
EPSS Percentile
97.8%
Details
CWE
CWE-399
Status
published
Products (8)
microsoft/isa_server
2004 sp3 (2 CPE variants)
microsoft/isa_server
2006 sp1 (2 CPE variants)
microsoft/office
microsoft/office
2003 sp3
microsoft/office
xp sp3
microsoft/office_web_components
2000 sp3
microsoft/office_web_components
2003 sp1 (2 CPE variants)
microsoft/office_web_components
xp sp3
Published
Aug 12, 2009
Tracked Since
Feb 18, 2026