ZeroHour
Cisco Talospublished ()ingested

Rule release for today

criticalVulnerability exploited in the wildimportance 60CVE-2009-0238

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2009-0238
Remote Code Execution in Microsoft Office Excel via Crafted Spreadsheet

CVE-2009-0238 is a remote code execution vulnerability in Microsoft Office Excel involving improper handling of a malformed object embedded in a specially crafted spreadsheet (code-injection class flaw, CWE-94). It is triggered when a user opens the malicious Excel file; no authentication or user interaction beyond opening the document is required. A successful attack lets the attacker run code in the context of the logged-in user and potentially take complete control of the affected system. Any organization running the affected Microsoft Office/Excel versions is exposed, with risk concentrated where users open spreadsheets from untrusted sources. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-14, confirming exploitation in the wild; ransomware use is unknown, no public proof-of-concept is known, and EPSS assigns a 43.1% probability of exploitation within 30 days (99th percentile).

Do: Apply Microsoft's security update for Office/Excel across the estate, prioritizing legacy Office installs and endpoints that handle untrusted spreadsheets, and verify via inventory that no unpatched Excel versions remain; per the CISA KEV listing and BOD 22-01, federal agencies must apply vendor mitigations by the required deadline or discontinue use. Until patched, discourage opening Excel files from untrusted sources and consider blocking or sandboxing spreadsheet attachments in email.

43% KEV
  • Microsoft Office (Excel component)
masshundreds of millions of Office/Excel seats historically; current unpatched exposure likely in the hundreds of thousands, mainly legacy or unmanaged Office…
Full article62 words · extracted from blog.talosintelligence.com · click to collapse

Friday, February 27, 2009 15:02

We've been busy again...

Microsoft Excel Code Execution (CVE-2009-0238):
Microsoft Excel contains a programming error that may allow a remote attacker to execute code on a vulnerable system. The problem occurs when Excel attempts to process a specially crafted document with an invalid object.

This issue is being actively exploited by Trojan.Mdropper.AC.

Details are available here: http://www.snort.org/vrt/advisories/vrt-rules-2009-02-27.html

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/rule-release-for-today-february-27th/