CVE-2009-0563 is a stack-based buffer overflow vulnerability affecting multiple versions of Microsoft Office Word, Office for Mac, Word Viewer, and the Office Compatibility Pack. This flaw allows remote attackers to execute arbitrary code by enticing a user to open a specially crafted Word document containing an invalid length field within a tag. The vulnerability carries a high CVSS score of 7.8, indicating a significant risk with high impact on confidentiality, integrity, and availability, requiring user interaction for exploitation. It is actively exploited in the wild, as confirmed by its presence in the KEV catalog, and has garnered considerable community discussion and media coverage, despite a lack of public exploit code in common repositories like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2000CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:* | ||
2003CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:* | ||
2004CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2004:*:*:*:*:macos:*:* | ||
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2007:sp1:*:*:*:*:*:* | ||
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2007:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.