CVE-2009-3129

Microsoft Excel: Featheader Record Memory Corruption

As of , CVE-2009-3129 in Microsoft Excel is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 3 March 2022
US federal deadline
24 March 202221 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.84Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.90 on 3 March 2022EPSS on the day CISA listed it.
Public exploit
1 Metasploit module and 2 Exploit-DB entries (1 verified)
Fix
No vendor link in CISA's entry

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

Microsoft Office Excel allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset.

CISA's description

Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset, aka "Excel Featheader Record Memory Corruption Vulnerability."

The CVE record's description, from microsoft

CVE published
11 November 2009
Assigned by
microsoft
CVSS
7.8 High (CVSS 3.1, from CISA-ADP)
CWE-787
Out-of-bounds Write
CWE-94
Improper Control of Generation of Code ('Code Injection')
CISA SSVC, exploitation
active
CISA SSVC, automatable
no
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. Exploit-DB published an exploit (EDB-ID 14706).
  3. Exploit-DB published an exploit (EDB-ID 16625).
  4. CISA added it to its list of exploited vulnerabilities.
  5. The US federal deadline to fix it.

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

Excel: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2016-7262Office Security Feature BypassMicrosoft ExcelPatch this weekEPSS 0.580.58
CVE-2019-1297Remote Code ExecutionMicrosoft ExcelPatch soon0.22

Read further