CVE-2009-1136 describes a critical arbitrary code execution vulnerability in the Microsoft Office Web Components Spreadsheet ActiveX control (OWC10/OWC11), affecting various Office and ISA Server products when used in Internet Explorer. This flaw, categorized as a CWE-94, allows remote attackers to execute arbitrary code via a crafted call to the msDataSourceObject method. With a CVSS score of 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C), it represents a high-severity risk due to its network-based attack vector, medium complexity, and complete compromise potential. The vulnerability was actively exploited in the wild in July and August 2009, with public exploit code available, including a Metasploit module and Proof-of-Concept on ExploitDB, despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2004CPE matchmatch criteria | cpe:2.3:a:microsoft:isa_server:2004:sp3:enterprise:*:*:*:*:* | ||
2004CPE matchmatch criteria | cpe:2.3:a:microsoft:isa_server:2004:sp3:standard:*:*:*:*:* | ||
2006CPE matchmatch criteria | cpe:2.3:a:microsoft:isa_server:2006:*:*:*:*:*:*:* | ||
2006CPE matchmatch criteria | cpe:2.3:a:microsoft:isa_server:2006:sp1:*:*:*:*:*:* | ||
2006CPE matchmatch criteria | cpe:2.3:a:microsoft:isa_server:2006:supportability:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.