CISA Known Exploited Vulnerability

CVE-2009-0557

Microsoft · Office

Microsoft Office Object Record Corruption Vulnerability

Date added
BOD 22-01 due date
CWE CWE-94
Ransomware Unknown

CISA description

Microsoft Office contains an object record corruption vulnerability that allows remote attackers to execute code via a crafted Excel file with a malformed record object.

Required action

Apply updates per vendor instructions.