CVE-2009-0238
KEVmassRemote Code Execution in Microsoft Office Excel via Crafted Spreadsheet
CISA: Microsoft Office Remote Code Execution
CVE-2009-0238 is a remote code execution vulnerability in Microsoft Office Excel involving improper handling of a malformed object embedded in a specially crafted spreadsheet (code-injection class flaw, CWE-94). It is triggered when a user opens the malicious Excel file; no authentication or user interaction beyond opening the document is required. A successful attack lets the attacker run code in the context of the logged-in user and potentially take complete control of the affected system. Any organization running the affected Microsoft Office/Excel versions is exposed, with risk concentrated where users open spreadsheets from untrusted sources. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-14, confirming exploitation in the wild; ransomware use is unknown, no public proof-of-concept is known, and EPSS assigns a 43.1% probability of exploitation within 30 days (99th percentile).
What to do: Apply Microsoft's security update for Office/Excel across the estate, prioritizing legacy Office installs and endpoints that handle untrusted spreadsheets, and verify via inventory that no unpatched Excel versions remain; per the CISA KEV listing and BOD 22-01, federal agencies must apply vendor mitigations by the required deadline or discontinue use. Until patched, discourage opening Excel files from untrusted sources and consider blocking or sandboxing spreadsheet attachments in email.
| Microsoft Office (Excel component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.
- Affected
- Microsoft Office
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- Office
- Weakness
- CWE-94