CVE-2009-0557CISA KEV
Microsoft Office Object Record Corruption Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Office contains an object record corruption vulnerability that allows remote attackers to execute code via a crafted Excel file with a malformed record object.
- Product
- Office
- Added to KEV
- 8 Jun 2022
- Federal remediation due
- 22 Jun 2022
- Known ransomware use
- Not reported