Microsoft Office Remote Code Execution (CVE-2009-0238).

Release Date: 13th April 2026

Impact : HIGH / CRITICAL

TLP Rating: Clear

The Department of Communication and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2009-0238 is a critical remote code execution vulnerability (CVSS ~9.3) in Microsoft Windows Internet Printing service (MS08-067-related RPC component exposure). It is caused by a stack-based buffer overflow in the handling of RPC requests over SMB (Server Message Block).

The flaw allows an attacker to send a specially crafted network request that overflows memory buffers in the Windows RPC service, enabling arbitrary code execution at SYSTEM level.

 

References

  1. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  2. https://www.cve.org/CVERecord?id=CVE-2009-0238
  3. https://nvd.nist.gov/vuln/detail/cve-2009-0238
  4. https://learn.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-067