CVE-2009-0556CISA KEV
Microsoft Office PowerPoint Code Injection Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an invalid index value that triggers memory corruption.
- Product
- Office
- Added to KEV
- 7 Jan 2026
- Federal remediation due
- 28 Jan 2026
- Known ransomware use
- Not reported