← Back

CVE-2009-1136

nvd nist
Published: Jul 15, 2009Modified: Apr 23, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 Gold and SP1, and Office Small Business Accounting 2006, when used in Internet Explorer, allows remote attackers to execute arbitrary code via a crafted call to the msDataSourceObject method, as exploited in the wild in July and August 2009, aka "Office Web Components HTML Script Vulnerability."

Affected (11)

4 products
Isa Server
Office
Office Web Components
Office Xp
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 2004 sp3
Version 2004 sp3
Version 2006
Version 2006 sp1
Version 2006 supportability
Microsoft
Version 2003
Version 2003 sp3
Microsoft
Version 2003 sp1
Version 2003 sp3
Version xp sp3
Version sp3

References (18)

Source: secure@microsoft.com
Vendor Advisory
Source: secure@microsoft.com
US Government Resource
Source: secure@microsoft.com
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

Timeline

No history available yet.