CVE-2009-0566
Last modified
CVE-2009-0566 is a vulnerability of currently unknown severity. Microsoft Office Publisher 2007 SP1 does not properly calculate object handler data for Publisher files, which allows remote attackers to execute arbitrary code via a crafted file in a legacy format that triggers memory corruption, aka "Pointer Dereference Vulnerability.". EPSS estimates a 28.95% chance of exploitation in the next 30 days.
Description
Microsoft Office Publisher 2007 SP1 does not properly calculate object handler data for Publisher files, which allows remote attackers to execute arbitrary code via a crafted file in a legacy format that triggers memory corruption, aka "Pointer Dereference Vulnerability."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Office Publisher | 2007 | Sp1 |
References
- http://www.us-cert.gov/cas/techalerts/TA09-195A.htmlUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA09-195A.htmlUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0566?
How severe is CVE-2009-0566?
How do I fix CVE-2009-0566?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-0559Stack-based buffer overflow in Excel in Microsoft Office 200…
- CVE-2009-0560Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 20…
- CVE-2009-0561Integer overflow in Excel in Microsoft Office 2000 SP3, Offi…
- CVE-2009-0562The Office Web Components ActiveX Control in Microsoft Offic…
- CVE-2009-0563Stack-based buffer overflow in Microsoft Office Word 2002 SP…7.8
- CVE-2009-0565Buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3,…
- CVE-2009-0567Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2009-0568The RPC Marshalling Engine (aka NDR) in Microsoft Windows 20…
- CVE-2009-0569Buffer overflow in Becky! Internet Mail 2.48.02 and earlier …
- CVE-2009-0570Directory traversal vulnerability in send.php in Ninja Desig…
- CVE-2009-0571admin.php in Ninja Designs Mailist 3.0 stores backup copies …
- CVE-2009-0572PHP remote file inclusion vulnerability in include/flatnux.p…
Are you affected by CVE-2009-0566?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
