CVE-2007-0671: Microsoft Office Excel Remote Code Execution Vulnerability

Published Feb 3, 2007
·
Updated

Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment or hosted on a malicious website. An attacker could leverage this vulnerability by creating a specially crafted Excel file, which, when opened, allowing an attacker to execute remote code on the affected system.

Other sources

Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.

Affected Software

38 affected components
Microsoft Access=2000
Microsoft Access=2002
Microsoft Access=2003
Microsoft Excel=2000
Microsoft Excel=2002
Microsoft Excel=2003
Microsoft Excel=2004
Microsoft Excel Viewer=2003
Microsoft FrontPage=2000
Microsoft FrontPage=2002
Microsoft FrontPage=2003
Microsoft InfoPath=2003
Microsoft Office=2000-sp3
Microsoft Office=2003-sp2
Microsoft Office=2004
Microsoft Office=xp-sp3
Microsoft OneNote=2003
Microsoft Outlook=2000
Microsoft Outlook=2002
Microsoft Outlook=2003
Microsoft PowerPoint=2000
Microsoft PowerPoint=2002
Microsoft PowerPoint=2003
Microsoft PowerPoint=2004
Microsoft Project=2000-sr1
Microsoft Project=2002-sp1
Microsoft Project=2003
Microsoft Publisher=2000
Microsoft Publisher=2002
Microsoft Publisher=2003
Microsoft Visio=2002-sp2
Microsoft Visio=2003
Microsoft Word=2000
Microsoft Word=2002
Microsoft Word=2003
Microsoft Word Viewer=2003
Microsoft Office
Microsoft Office Macos=2004

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Follow applicable BOD 22-01 guidance for cloud services.

  2. Compensating control

    Discontinue use of the affected Microsoft Office products if mitigations are unavailable: Microsoft Access 2010; Microsoft InfoPath 2016; Microsoft Office; Microsoft Office Excel; Microsoft Office Excel Viewer; Microsoft Office FrontPage; Microsoft Office Word; Microsoft Office Word Viewer; Microsoft OneNote 2010; Microsoft Outlook; Microsoft PowerPoint 2010; Microsoft Project 2010; Microsoft Publisher 2010; Microsoft Visio Standard.

Event History

Feb 3, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·01:28 AM
DescriptionSeverityAffected Software
Aug 12, 2025
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2007-0671?

CVE-2007-0671 is considered to have a moderate severity, allowing remote user-assisted attackers to execute arbitrary code.

2

How do I fix CVE-2007-0671?

To fix CVE-2007-0671, ensure that you have installed the latest security updates for affected Microsoft Office products.

3

Which software versions are affected by CVE-2007-0671?

CVE-2007-0671 affects Microsoft Excel 2000, XP, 2003, and 2004 for Mac, as well as several other Microsoft Office products.

4

Can CVE-2007-0671 be exploited remotely?

Yes, CVE-2007-0671 can be exploited remotely through user-assisted actions, potentially leading to arbitrary code execution.

5

What types of attacks are associated with CVE-2007-0671?

CVE-2007-0671 is associated with targeted zero-day attacks that take advantage of unspecified vulnerabilities in Microsoft Office applications.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203