CVE-2009-0238: Microsoft Office Remote Code Execution
Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC.
Other sources
Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
- Compensating control
If mitigations are unavailable, discontinue use of the affected products: Microsoft Excel; Microsoft Office; Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint; Microsoft Office Excel; Microsoft Office Excel Viewer; Microsoft Office Viewer.
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0238?
CVE-2009-0238 has a critical severity rating due to its potential for remote code execution.
How do I fix CVE-2009-0238?
To fix CVE-2009-0238, users should update to the latest security patches provided by Microsoft for the affected versions of Excel.
Which versions of Microsoft Office are affected by CVE-2009-0238?
CVE-2009-0238 affects Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, 2007 SP1, along with various versions of Excel Viewer and the Compatibility Pack.
What type of attack does CVE-2009-0238 enable?
CVE-2009-0238 enables remote attackers to execute arbitrary code on affected systems through crafted Excel files.
Is there a workaround for CVE-2009-0238?
The most effective workaround for CVE-2009-0238 is to avoid opening untrusted Excel files until the software is updated.