Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC.

Project Subscriptions

Vendors Products
Microsoft Subscribe
Excel Viewer Subscribe
Office Compatibility Pack Subscribe
Office Excel Subscribe
Office Excel Viewer Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 14 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Apr 2026 17:45:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-04-14T00:00:00+00:00', 'dueDate': '2026-04-28T00:00:00+00:00'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-04-15T03:58:09.636Z

Reserved: 2009-01-20T00:00:00.000Z

Link: CVE-2009-0238

cve-icon Vulnrichment

Updated: 2024-08-07T04:24:18.463Z

cve-icon NVD

Status : Deferred

Published: 2009-02-25T16:30:00.343

Modified: 2026-04-14T18:16:39.080

Link: CVE-2009-0238

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses