← Back to browse · API

CVE-2009-0556

Severity
HIGH
CVSS
8.8
EPSS
0.67539
Risk score
83.84
CISA KEV
Yes
PoC
No
Published
2026-01-07
Modified
2026-01-07
First seen
2026-08-07
Aliases
EUVD-2009-0560, GHSA-W25V-2MF8-86HR
Products
Microsoft:Office, n/a:n/a n/a
Sources
euvd EUVD-2009-0560
cisa.gov CVE-2009-0556

Description

Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an invalid index value that triggers memory corruption.

References