CVE-2007-0671: Microsoft Office Excel Remote Code Execution Vulnerability
Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment or hosted on a malicious website. An attacker could leverage this vulnerability by creating a specially crafted Excel file, which, when opened, allowing an attacker to execute remote code on the affected system.
Other sources
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
- Compensating control
Discontinue use of the affected Microsoft Office products if mitigations are unavailable: Microsoft Access 2010; Microsoft InfoPath 2016; Microsoft Office; Microsoft Office Excel; Microsoft Office Excel Viewer; Microsoft Office FrontPage; Microsoft Office Word; Microsoft Office Word Viewer; Microsoft OneNote 2010; Microsoft Outlook; Microsoft PowerPoint 2010; Microsoft Project 2010; Microsoft Publisher 2010; Microsoft Visio Standard.
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0671?
CVE-2007-0671 is considered to have a moderate severity, allowing remote user-assisted attackers to execute arbitrary code.
How do I fix CVE-2007-0671?
To fix CVE-2007-0671, ensure that you have installed the latest security updates for affected Microsoft Office products.
Which software versions are affected by CVE-2007-0671?
CVE-2007-0671 affects Microsoft Excel 2000, XP, 2003, and 2004 for Mac, as well as several other Microsoft Office products.
Can CVE-2007-0671 be exploited remotely?
Yes, CVE-2007-0671 can be exploited remotely through user-assisted actions, potentially leading to arbitrary code execution.
What types of attacks are associated with CVE-2007-0671?
CVE-2007-0671 is associated with targeted zero-day attacks that take advantage of unspecified vulnerabilities in Microsoft Office applications.