CVE-2009-0238
Last modified
CVE-2009-0238 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC.. CISA has confirmed active exploitation in the wild. EPSS estimates a 43.06% chance of exploitation in the next 30 days.
Description
Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Excel | 2000 | Sp3 |
| Microsoft | Excel | 2002 | Sp3 |
| Microsoft | Excel | 2003 | Sp3 |
| Microsoft | Excel | 2007 | Sp1 |
| Microsoft | Excel Viewer | All versions | — |
| Microsoft | Office | 2004 | — |
| Microsoft | Office | 2008 | — |
| Microsoft | Office Compatibility Pack | 2007 | Sp1 |
| Microsoft | Office Excel Viewer | All versions | — |
| Microsoft | Office Excel Viewer | 2003 | Sp3 |
References
- http://blogs.zdnet.com/security/?p=2658Broken Link
- http://isc.sans.org/diary.html?storyid=5923Press/Media Coverage
- http://securitytracker.com/id?1021744Broken Link
- http://www.securityfocus.com/bid/33870Broken Link
- http://www.us-cert.gov/cas/techalerts/TA09-104A.htmlUS Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48875Third Party Advisory
- http://blogs.zdnet.com/security/?p=2658Broken Link
- http://isc.sans.org/diary.html?storyid=5923Press/Media Coverage
- http://securitytracker.com/id?1021744Broken Link
- http://www.securityfocus.com/bid/33870Broken Link
- http://www.us-cert.gov/cas/techalerts/TA09-104A.htmlUS Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48875Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-0238US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2009-0238?
How severe is CVE-2009-0238?
How do I fix CVE-2009-0238?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-0232Integer overflow in the Embedded OpenType (EOT) Font Engine …
- CVE-2009-0233The DNS Resolver Cache Service (aka DNSCache) in Windows DNS…
- CVE-2009-0234The DNS Resolver Cache Service (aka DNSCache) in Windows DNS…
- CVE-2009-0235Stack-based buffer overflow in the Word 97 text converter in…
- CVE-2009-0236Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2009-0237Cross-site scripting (XSS) vulnerability in cookieauth.dll i…
- CVE-2009-0239Cross-site scripting (XSS) vulnerability in Windows Search 4…
- CVE-2009-0240listing.php in WebSVN 2.0 and possibly 1.7 beta, when using …
- CVE-2009-0241Stack-based buffer overflow in the process_path function in …
- CVE-2009-0242Rejected reason: gmetad in Ganglia 3.1.1, when supporting mu…
- CVE-2009-0243Microsoft Windows does not properly enforce the Autorun and …
- CVE-2009-0244Directory traversal vulnerability in the OBEX FTP Service in…8.8
Are you affected by CVE-2009-0238?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
