Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; Microsoft Office Word Viewer 2003 SP3; Microsoft Office Word Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a Word document with a crafted tag containing an invalid length field, aka "Word Buffer Overflow Vulnerability."
Published Jun 10, 2009 ·Due Jun 22, 2022
7.8
HIGHCVSS 3.1
EPSS 62.83%
Description
Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; Microsoft Office Word Viewer 2003 SP3; Microsoft Office Word Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a Word document with a crafted tag containing an invalid length field, aka "Word Buffer Overflow Vulnerability."
Affected products
No data.
- 2000
- 2003
- 2004
- 2007
- 2007
- 2008
- xp
- 2007
- 2007
- n/a
- 2003
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Date Added
Jun 8, 2022
Patch Due
Jun 22, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 10, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (35 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 62.83% (0.62828) | 99.17th | v5 (v2026.06.15) |
| Jun 15, 2026 | 62.83% (0.62828) | 99.09th | v5 (v2026.06.15) |
| Feb 28, 2026 | 79.92% (0.79917) | 99.07th | v4 (v2025.03.14) |
| Oct 22, 2025 | 81.80% (0.81800) | 99.14th | v4 (v2025.03.14) |
| Jul 25, 2025 | 80.02% (0.80017) | 99.05th | v4 (v2025.03.14) |
| Jun 18, 2025 | 77.80% (0.77797) | 98.94th | v4 (v2025.03.14) |
| Jun 10, 2025 | 70.11% (0.70109) | 98.56th | v4 (v2025.03.14) |
| Mar 30, 2025 | 72.37% (0.72374) | 98.68th | v4 (v2025.03.14) |
| Mar 29, 2025 | 80.16% (0.80157) | 98.86th | v4 (v2025.03.14) |
| Mar 19, 2025 | 72.37% (0.72374) | 98.65th | v4 (v2025.03.14) |
| Mar 17, 2025 | 69.07% (0.69066) | 98.53th | v4 (v2025.03.14) |
| Mar 1, 2025 | 84.70% (0.84703) | 98.78th | v3 (v2023.03.01) |
| Jan 24, 2025 | 86.08% (0.86076) | 98.82th | v3 (v2023.03.01) |
| Dec 19, 2024 | 88.54% (0.88538) | 98.95th | v3 (v2023.03.01) |
| Dec 17, 2024 | 91.98% (0.91979) | 99.18th | v3 (v2023.03.01) |
| Nov 13, 2024 | 89.52% (0.89521) | 98.87th | v3 (v2023.03.01) |
| Jun 29, 2024 | 88.09% (0.88089) | 98.71th | v3 (v2023.03.01) |
| Jun 23, 2024 | 73.35% (0.73349) | 98.13th | v3 (v2023.03.01) |
| May 17, 2024 | 78.27% (0.78274) | 98.23th | v3 (v2023.03.01) |
| Dec 9, 2023 | 83.28% (0.83278) | 98.13th | v3 (v2023.03.01) |
| Oct 28, 2023 | 86.33% (0.86327) | 98.23th | v3 (v2023.03.01) |
| Sep 13, 2023 | 90.31% (0.90311) | 98.41th | v3 (v2023.03.01) |
| Jul 29, 2023 | 90.41% (0.90407) | 98.38th | v3 (v2023.03.01) |
| Apr 29, 2023 | 89.55% (0.89551) | 98.20th | v3 (v2023.03.01) |
| Mar 16, 2023 | 90.04% (0.90043) | 98.18th | v3 (v2023.03.01) |
| Mar 7, 2023 | 90.42% (0.90418) | 98.20th | v3 (v2023.03.01) |
| Mar 6, 2023 | 46.72% (0.46718) | 98.56th | v2 (v2022.01.01) |
| Nov 11, 2022 | 46.72% (0.46718) | 98.49th | v2 (v2022.01.01) |
| Sep 10, 2022 | 49.76% (0.49756) | 98.63th | v2 (v2022.01.01) |
| Jul 18, 2022 | 55.10% (0.55095) | 98.72th | v2 (v2022.01.01) |
| Jul 17, 2022 | 9.92% (0.09915) | 94.34th | v2 (v2022.01.01) |
| Jul 9, 2022 | 55.10% (0.55095) | 98.71th | v2 (v2022.01.01) |
| May 5, 2022 | 57.79% (0.57789) | 98.73th | v2 (v2022.01.01) |
| Mar 1, 2022 | 60.01% (0.60013) | 98.64th | v2 (v2022.01.01) |
| Feb 4, 2022 | 67.16% (0.67160) | 98.89th | v2 (v2022.01.01) |
References (10)
- http://osvdb.org/54959 vdb-entryx_refsource_OSVDBBroken Link
- http://www.securityfocus.com/archive/1/504204/100/0/threaded mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/35188 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1022356 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://www.us-cert.gov/cas/techalerts/TA09-160A.html third-party-advisoryx_refsource_CERTBroken LinkThird Party AdvisoryUS Government Resource
- http://www.vupen.com/english/advisories/2009/1546 vdb-entryx_refsource_VUPENBroken Link
- http://www.zerodayinitiative.com/advisories/ZDI-09-035 x_refsource_MISCThird Party AdvisoryVDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-027 vendor-advisoryx_refsource_MSPatchVendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6133 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-0563 government-resourceUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| http://osvdb.org/54959 | vdb-entryx_refsource_OSVDBBroken Link | |
| http://www.securityfocus.com/archive/1/504204/100/0/threaded | mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry | |
| http://www.securityfocus.com/bid/35188 | vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id?1022356 | vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry | |
| http://www.us-cert.gov/cas/techalerts/TA09-160A.html | third-party-advisoryx_refsource_CERTBroken LinkThird Party AdvisoryUS Government Resource | |
| http://www.vupen.com/english/advisories/2009/1546 | vdb-entryx_refsource_VUPENBroken Link | |
| http://www.zerodayinitiative.com/advisories/ZDI-09-035 | x_refsource_MISCThird Party AdvisoryVDB Entry | |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-027 | vendor-advisoryx_refsource_MSPatchVendor Advisory | |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6133 | vdb-entrysignaturex_refsource_OVALBroken Link | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-0563 | government-resourceUS Government Resource |
Change history (0)
No recorded changes yet.