CISA Identifies Microsoft Office and HPE OneView Vulnerabilities Under Active Exploitation
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently flagged two significant vulnerabilities impacting Microsoft Office and Hewlett Packard Enterprise (HPE) OneView. These vulnerabilities were added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on January 7, 2026, due to evidence of active exploitation. The first vulnerability, CVE-2009-0556, affects Microsoft Office PowerPoint and has a CVSS score of 8.8, allowing remote attackers to execute arbitrary code via memory corruption.
The second vulnerability, CVE-2025-37164, is a critical code injection flaw in HPE OneView, rated with a CVSS score of 10.0. This vulnerability permits a remote unauthenticated user to perform remote code execution. HPE disclosed that all versions prior to 11.00 are affected and has provided hotfixes for versions 5.20 through 10. Organizations are strongly advised to implement these updates to mitigate potential exploitation risks.
While the specific scope and source of attacks exploiting these vulnerabilities remain unclear, a report from eSentire on December 23, 2025, indicated the availability of a detailed proof-of-concept (PoC) exploit for CVE-2025-37164. The public release of PoC code heightens the risk for organizations using vulnerable versions of the software.
According to Binding Operational Directive (BOD) 22-01, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply necessary fixes by January 28, 2026, to secure their networks against these active threats. The urgency of these updates reflects the critical nature of the vulnerabilities and the potential for significant impact on organizational security.
Understanding the Risks
Organizations running affected versions of Microsoft Office and HPE OneView should be aware of the heightened risk posed by these vulnerabilities. With CVE-2025-37164 allowing unauthenticated remote code execution, the potential for unauthorized access and data breaches is significant. The presence of exploit code in the public domain further amplifies this risk.
It is crucial for IT departments and security teams to prioritize patching these vulnerabilities and to ensure that all systems are updated to the latest versions. Regular monitoring for updates and vulnerabilities should be part of an ongoing security strategy to protect against potential exploitation.
Key Takeaways
- Update Microsoft Office to the latest version to mitigate the CVE-2009-0556 vulnerability.
- Apply hotfixes for HPE OneView versions 5.20 through 10 to address CVE-2025-37164.
- Monitor for any new security advisories related to these vulnerabilities.
- Implement a regular patch management process to ensure timely updates across all systems.
- Educate staff about the risks associated with unpatched vulnerabilities and the importance of security updates.
Key Terms & Concepts
- CVE: In this article, CVE refers to a standardized identifier for publicly known cybersecurity vulnerabilities.
- CVSS: CVSS is a scoring system that assesses the severity of vulnerabilities, with higher scores indicating greater risk.
- Proof-of-concept (PoC): A proof-of-concept exploit is a demonstration that shows how a vulnerability can be exploited.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.