Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC
Published Feb 25, 2009 ·Due Apr 28, 2026
8.8
HIGHCVSS 3.1
EPSS 43.21%
Description
Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC.
Affected products
No data.
- 2000
- 2002
- 2003
- 2007
- n/a
- 2004
- 2008
- 2007
- n/a
- 2003
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Date Added
Apr 14, 2026
Patch Due
Apr 28, 2026
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Apr 14, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (33 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 43.21% (0.43212) | 98.69th | v5 (v2026.06.15) |
| Jun 15, 2026 | 43.06% (0.43063) | 98.55th | v5 (v2026.06.15) |
| Jun 8, 2026 | 74.75% (0.74749) | 98.88th | v4 (v2025.03.14) |
| May 22, 2026 | 72.86% (0.72860) | 98.80th | v4 (v2025.03.14) |
| Apr 23, 2026 | 74.91% (0.74913) | 98.88th | v4 (v2025.03.14) |
| Apr 15, 2026 | 81.14% (0.81142) | 99.16th | v4 (v2025.03.14) |
| Mar 30, 2025 | 58.07% (0.58067) | 98.00th | v4 (v2025.03.14) |
| Mar 29, 2025 | 63.80% (0.63803) | 97.78th | v4 (v2025.03.14) |
| Mar 17, 2025 | 58.07% (0.58067) | 97.96th | v4 (v2025.03.14) |
| Mar 3, 2025 | 77.17% (0.77173) | 98.49th | v3 (v2023.03.01) |
| Dec 22, 2024 | 72.03% (0.72027) | 98.26th | v3 (v2023.03.01) |
| Dec 17, 2024 | 74.64% (0.74642) | 98.35th | v3 (v2023.03.01) |
| Nov 16, 2024 | 46.50% (0.46499) | 97.56th | v3 (v2023.03.01) |
| Oct 11, 2024 | 49.15% (0.49154) | 97.57th | v3 (v2023.03.01) |
| Sep 5, 2024 | 50.25% (0.50250) | 97.59th | v3 (v2023.03.01) |
| Jul 31, 2024 | 54.84% (0.54840) | 97.69th | v3 (v2023.03.01) |
| Jun 24, 2024 | 61.12% (0.61118) | 97.81th | v3 (v2023.03.01) |
| May 21, 2024 | 61.78% (0.61776) | 97.81th | v3 (v2023.03.01) |
| Apr 16, 2024 | 59.69% (0.59693) | 97.71th | v3 (v2023.03.01) |
| Mar 10, 2024 | 56.69% (0.56693) | 97.60th | v3 (v2023.03.01) |
| Feb 2, 2024 | 55.38% (0.55385) | 97.39th | v3 (v2023.03.01) |
| Aug 26, 2023 | 64.85% (0.64853) | 97.44th | v3 (v2023.03.01) |
| Jul 15, 2023 | 65.06% (0.65056) | 97.42th | v3 (v2023.03.01) |
| May 31, 2023 | 68.83% (0.68831) | 97.50th | v3 (v2023.03.01) |
| Apr 15, 2023 | 67.10% (0.67099) | 97.39th | v3 (v2023.03.01) |
| Mar 7, 2023 | 70.33% (0.70326) | 97.42th | v3 (v2023.03.01) |
| Mar 6, 2023 | 46.72% (0.46718) | 98.56th | v2 (v2022.01.01) |
| Jul 29, 2022 | 46.72% (0.46718) | 98.44th | v2 (v2022.01.01) |
| Jul 18, 2022 | 49.76% (0.49756) | 98.61th | v2 (v2022.01.01) |
| Jul 17, 2022 | 9.92% (0.09915) | 94.34th | v2 (v2022.01.01) |
| May 28, 2022 | 49.76% (0.49756) | 98.57th | v2 (v2022.01.01) |
| Mar 26, 2022 | 55.10% (0.55095) | 98.49th | v2 (v2022.01.01) |
| Feb 4, 2022 | 57.79% (0.57789) | 98.52th | v2 (v2022.01.01) |
References (12)
- http://blogs.zdnet.com/security/?p=2658 x_refsource_MISCBroken Link
- http://isc.sans.org/diary.html?storyid=5923 x_refsource_MISCPress/Media Coverage
- http://securitytracker.com/id?1021744 vdb-entryx_refsource_SECTRACKBroken Link
- http://www.microsoft.com/technet/security/advisory/968272.mspx x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/bid/33870 vdb-entryx_refsource_BIDBroken Link
- http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-022310-4202-99 x_refsource_MISCBroken Link
- http://www.us-cert.gov/cas/techalerts/TA09-104A.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vupen.com/english/advisories/2009/1023 vdb-entryx_refsource_VUPENBroken Link
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-009 vendor-advisoryx_refsource_MSVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48875 vdb-entryx_refsource_XFThird Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5968 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-0238 government-resourceUS Government Resource
Change history (0)
No recorded changes yet.