Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.8
Microsoft Office Excel Malicious File Attack
Known exploited
CVE-2009-0238
CVE-2009-0238
Summary
Opening a specially crafted Excel file in Microsoft Office Excel can give an attacker control over your computer. This affects users who open Excel files from untrusted sources. Update your Microsoft Office software to the latest version to prevent this risk.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| microsoft | office | All versions | – |
| microsoft | excel | 2004 | – |
| microsoft | excel_viewer | All versions | – |
| microsoft | office | 2008 | – |
| microsoft | office_compatibility_pack | 2007 | – |
| microsoft | office_excel | 2000 | – |
| microsoft | office_excel | 2002 | – |
| microsoft | office_excel | 2003 | – |
| microsoft | office_excel | 2007 | – |
| microsoft | office_excel_viewer | All versions | – |
| microsoft | office_excel_viewer | 2003 | – |
| microsoft | office_excel_viewer | 2003 | – |
Original title
Microsoft Office Remote Code Execution
Original description
Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.
Vulnerability type
CWE-94
Code Injection
- http://www.microsoft.com/technet/security/advisory/968272.mspx Vendor Advisory
- http://www.securityfocus.com/bid/33870
- http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-022310...
- http://www.us-cert.gov/cas/techalerts/TA09-104A.html US Government Resource
- http://www.vupen.com/english/advisories/2009/1023
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-00...
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48875
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3...
- http://blogs.zdnet.com/security/?p=2658
- http://isc.sans.org/diary.html?storyid=5923
- http://securitytracker.com/id?1021744
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-...
Published: 14 Apr 2026 · Updated: 14 Apr 2026 · First seen: 14 Apr 2026