← Back

CVE-2009-0238

nvd nist
Published: Feb 25, 2009Modified: Apr 22, 2026CISA KEV

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC.

Affected (10)

5 products
Excel
Excel Viewer
Office
Office Compatibility Pack
Office Excel Viewer
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 2000 sp3
Version 2002 sp3
Version 2003 sp3
Version 2007 sp1
All versions
Microsoft
Version 2004
Version 2008
Version 2007 sp1
Microsoft
All versions
Version 2003 sp3

References (23)

Source: secure@microsoft.com
Broken Link
Source: secure@microsoft.com
Press/Media Coverage
Source: secure@microsoft.com
Broken Link
Source: secure@microsoft.com
Vendor Advisory
Source: secure@microsoft.com
Broken Link
Source: secure@microsoft.com
US Government Resource
Source: secure@microsoft.com
Broken Link
Source: secure@microsoft.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Press/Media Coverage
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.