ZeroHour

CVE-2009-0238

KEVmass

Remote Code Execution in Microsoft Office Excel via Crafted Spreadsheet

CISA: Microsoft Office Remote Code Execution

CVSS
EPSS
43%p99
Published
KEV added
AI analysis

CVE-2009-0238 is a remote code execution vulnerability in Microsoft Office Excel involving improper handling of a malformed object embedded in a specially crafted spreadsheet (code-injection class flaw, CWE-94). It is triggered when a user opens the malicious Excel file; no authentication or user interaction beyond opening the document is required. A successful attack lets the attacker run code in the context of the logged-in user and potentially take complete control of the affected system. Any organization running the affected Microsoft Office/Excel versions is exposed, with risk concentrated where users open spreadsheets from untrusted sources. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-14, confirming exploitation in the wild; ransomware use is unknown, no public proof-of-concept is known, and EPSS assigns a 43.1% probability of exploitation within 30 days (99th percentile).

What to do: Apply Microsoft's security update for Office/Excel across the estate, prioritizing legacy Office installs and endpoints that handle untrusted spreadsheets, and verify via inventory that no unpatched Excel versions remain; per the CISA KEV listing and BOD 22-01, federal agencies must apply vendor mitigations by the required deadline or discontinue use. Until patched, discourage opening Excel files from untrusted sources and consider blocking or sandboxing spreadsheet attachments in email.

Affected
Microsoft Office (Excel component)
Estimated exposure
masshundreds of millions of Office/Excel seats historically; current unpatched exposure likely in the hundreds of thousands, mainly legacy or unmanaged Office… — Microsoft Office/Excel has one of the largest desktop software install bases in the world (hundreds of millions of seats), but as a 2009-era flaw it is presumed patched on most maintained systems, leaving mostly legacy deployments still…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.

CISA Known Exploited Vulnerability
Affected
Microsoft Office
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Office
Weakness
CWE-94

In the news