ZeroHour

CVE-2007-0671

KEVmass

Remote Code Execution in Microsoft Office Excel via Crafted Spreadsheet Files

CISA: Microsoft Office Excel Remote Code Execution Vulnerability

CVSS
EPSS
42%p99
Published
KEV added
AI analysis

CVE-2007-0671 is a remote code execution vulnerability in the Microsoft Office Excel spreadsheet engine. An attacker triggers it by persuading a user to open a specially crafted Excel file, typically delivered as an email attachment or hosted on a malicious website, corrupting Excel's file parsing and handing control to the attacker. Successful exploitation allows arbitrary code execution in the context of the logged-on user, letting the attacker install programs, view or modify data, or take over the workstation. Any user of the affected Microsoft Office/Excel versions who opens spreadsheets from untrusted sources is exposed; the source data does not specify affected version ranges, so defenders should consult Microsoft's advisory for their versions. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-12, indicating known exploitation in the wild, and carries a high EPSS score of 42.4% (99th percentile); no public proof-of-concept is known.

What to do: Apply the Microsoft security updates and mitigations for this CVE per vendor instructions; federal agencies must follow BOD 22-01 timelines or discontinue use if mitigations are unavailable. Until patched, do not open Excel attachments or downloaded spreadsheets from untrusted sources and warn users about spreadsheet-borne attacks. Inventory endpoints for the affected Office/Excel versions and prioritize patching high-risk and frequently emailed users.

Affected
Microsoft Office (Excel)
Estimated exposure
masshundreds of millions of Office/Excel users (legacy-version subset; any endpoint opening untrusted spreadsheets) — Microsoft Office is the dominant desktop productivity suite with hundreds of millions of installed users across enterprise and consumer endpoints, so the population capable of opening a malicious Excel file is at least in the hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment or hosted on a malicious website. An attacker could leverage this vulnerability by creating a specially crafted Excel file, which, when opened, allowing an attacker to execute remote code on the affected system.

CISA Known Exploited Vulnerability
Affected
Microsoft Office
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Office

In the news