CVE-2009-0238
Last modified
CVE-2009-0238 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC.. CISA has confirmed active exploitation in the wild. EPSS estimates a 43.06% chance of exploitation in the next 30 days.
Description
Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Excel | 2000 | Sp3 |
| Microsoft | Excel | 2002 | Sp3 |
| Microsoft | Excel | 2003 | Sp3 |
| Microsoft | Excel | 2007 | Sp1 |
| Microsoft | Excel Viewer | All versions | — |
| Microsoft | Office | 2004 | — |
| Microsoft | Office | 2008 | — |
| Microsoft | Office Compatibility Pack | 2007 | Sp1 |
| Microsoft | Office Excel Viewer | All versions | — |
| Microsoft | Office Excel Viewer | 2003 | Sp3 |
References
- http://blogs.zdnet.com/security/?p=2658Broken Link
- http://isc.sans.org/diary.html?storyid=5923Press/Media Coverage
- http://securitytracker.com/id?1021744Broken Link
- http://www.securityfocus.com/bid/33870Broken Link
- http://www.us-cert.gov/cas/techalerts/TA09-104A.htmlUS Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48875Third Party Advisory
- http://blogs.zdnet.com/security/?p=2658Broken Link
- http://isc.sans.org/diary.html?storyid=5923Press/Media Coverage
- http://securitytracker.com/id?1021744Broken Link
- http://www.securityfocus.com/bid/33870Broken Link
- http://www.us-cert.gov/cas/techalerts/TA09-104A.htmlUS Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48875Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-0238US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2009-0238?
How severe is CVE-2009-0238?
How do I fix CVE-2009-0238?
Are you affected by CVE-2009-0238?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
