Back to search
CVE-2009-0556
Published: Apr 3, 2009
Modified: Jan 8, 2026
PUBLISHED
Description
Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Memory Corruption Vulnerability."
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://www.zerodayinitiative.com/advisories/ZDI-09-019
x_refsource_MISC
ADV-2009-1290
vdb-entry
x_refsource_VUPEN
53182
vdb-entry
x_refsource_OSVDB
MS09-017
vendor-advisory
x_refsource_MS
powerpoint-unspecified-code-execution(49632)
vdb-entry
x_refsource_XF
34351
vdb-entry
x_refsource_BID
ADV-2009-0915
vdb-entry
x_refsource_VUPEN
oval:org.mitre.oval:def:6279
vdb-entry
signature
x_refsource_OVAL
34572
third-party-advisory
x_refsource_SECUNIA
1021967
vdb-entry
x_refsource_SECTRACK
TA09-132A
third-party-advisory
x_refsource_CERT
http://www.microsoft.com/technet/security/advisory/969136.mspx
x_refsource_CONFIRM
VU#627331
third-party-advisory
x_refsource_CERT-VN
20090512 ZDI-09-019: Microsoft Office PowerPoint OutlineTextRefAtom Parsing Memory Corruption Vulnerability
mailing-list
x_refsource_BUGTRAQ
oval:org.mitre.oval:def:6204
vdb-entry
signature
x_refsource_OVAL
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now