CVE-2009-0563
Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; Microsoft Office Word Viewer 2003 SP3; Microsoft Office Word Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a Word document with a crafted tag containing an invalid length field, aka "Word Buffer Overflow Vulnerability."
- Affected products
- Office Compatibility Pack For Word, Office Word, Office Word Viewer, Office For Mac, Open Xml File Format Converter For Mac
- Microsoft Office
- = 2000, 2003, 2004, 2007, 2008, xp
- Microsoft Office Compatibility Pack
- = 2007
- Microsoft Office Word Viewer
- All versions
- Microsoft Open Xml File Format Converter
- All versions
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 63.1% (99th percentile)
- Weakness
- CWE-787
- NVD status
- Analyzed
- Published
- 2009-06-10
CVE-2009-0563 at NVD
1 known exploit for CVE-2009-0563
Proof-of-concept code and exploit modules indexed by Sploitus