CVE-2007-0671
KEVmassRemote Code Execution in Microsoft Office Excel via Crafted Spreadsheet Files
CISA: Microsoft Office Excel Remote Code Execution Vulnerability
CVE-2007-0671 is a remote code execution vulnerability in the Microsoft Office Excel spreadsheet engine. An attacker triggers it by persuading a user to open a specially crafted Excel file, typically delivered as an email attachment or hosted on a malicious website, corrupting Excel's file parsing and handing control to the attacker. Successful exploitation allows arbitrary code execution in the context of the logged-on user, letting the attacker install programs, view or modify data, or take over the workstation. Any user of the affected Microsoft Office/Excel versions who opens spreadsheets from untrusted sources is exposed; the source data does not specify affected version ranges, so defenders should consult Microsoft's advisory for their versions. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-12, indicating known exploitation in the wild, and carries a high EPSS score of 42.4% (99th percentile); no public proof-of-concept is known.
What to do: Apply the Microsoft security updates and mitigations for this CVE per vendor instructions; federal agencies must follow BOD 22-01 timelines or discontinue use if mitigations are unavailable. Until patched, do not open Excel attachments or downloaded spreadsheets from untrusted sources and warn users about spreadsheet-borne attacks. Inventory endpoints for the affected Office/Excel versions and prioritize patching high-risk and frequently emailed users.
| Microsoft Office (Excel) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment or hosted on a malicious website. An attacker could leverage this vulnerability by creating a specially crafted Excel file, which, when opened, allowing an attacker to execute remote code on the affected system.
- Affected
- Microsoft Office
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- Office