ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds Microsoft Internet Explorer, Microsoft Office Excel, and WinRAR flaws to its Known Exploited Vulnerabilities catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2013-3893CVE-2007-0671CVE-2025-8088

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2007-0671
Remote Code Execution in Microsoft Office Excel via Crafted Spreadsheet Files

CVE-2007-0671 is a remote code execution vulnerability in the Microsoft Office Excel spreadsheet engine. An attacker triggers it by persuading a user to open a specially crafted Excel file, typically delivered as an email attachment or hosted on a malicious website, corrupting Excel's file parsing and handing control to the attacker. Successful exploitation allows arbitrary code execution in the context of the logged-on user, letting the attacker install programs, view or modify data, or take over the workstation. Any user of the affected Microsoft Office/Excel versions who opens spreadsheets from untrusted sources is exposed; the source data does not specify affected version ranges, so defenders should consult Microsoft's advisory for their versions. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-12, indicating known exploitation in the wild, and carries a high EPSS score of 42.4% (99th percentile); no public proof-of-concept is known.

Do: Apply the Microsoft security updates and mitigations for this CVE per vendor instructions; federal agencies must follow BOD 22-01 timelines or discontinue use if mitigations are unavailable. Until patched, do not open Excel attachments or downloaded spreadsheets from untrusted sources and warn users about spreadsheet-borne attacks. Inventory endpoints for the affected Office/Excel versions and prioritize patching high-risk and frequently emailed users.

42% KEV
  • Microsoft Office (Excel)
masshundreds of millions of Office/Excel users (legacy-version subset; any endpoint opening untrusted spreadsheets)
CVE-2013-3893
Memory Corruption RCE in Microsoft Internet Explorer

CVE-2013-3893 is a resource-management (memory corruption) flaw in Microsoft Internet Explorer that can allow remote code execution (CWE-399). It is triggered remotely, typically when a user views attacker-controlled web content in a vulnerable version of Internet Explorer. A successful attacker gains the ability to execute arbitrary code in the context of the current user, potentially compromising the workstation. Organizations still running Internet Explorer, which CISA notes may be end-of-life (EoL) and/or end-of-service (EoS), are affected; specific affected version ranges were not provided in the source data. The flaw was patched in Microsoft's October 2013 Patch Tuesday after being exploited in the wild (Operation DeputyDog, per related reporting), and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-08-12 with a very high EPSS of 85.9% (100th percentile), indicating active or imminent exploitation.

Do: Apply mitigations per Microsoft's vendor instructions and follow applicable BOD 22-01 guidance for cloud services, or discontinue use of Internet Explorer if mitigations are unavailable, per CISA's required action. Verify that affected systems have the October 2013 Patch Tuesday (or later) cumulative Internet Explorer security updates installed, and audit your estate for remaining legacy IE usage. Where IE is still needed for legacy sites, migrate to Microsoft Edge with IE mode and treat in-the-wild exploitation as likely given the KEV listing and 85.9% EPSS.

86% KEV
  • Microsoft Internet Explorer
masstens to hundreds of millions of legacy Windows devices historically capable of running IE; current actively used legacy IE installs unknown but plausibly in…
CVE-2025-8088
WinRAR Path Traversal (CVE-2025-8088) Enables Arbitrary Code Execution

A path traversal flaw (CWE-35) in the Windows version of WinRAR allows attackers to achieve arbitrary code execution by delivering a specially crafted archive file that writes outside the expected location when it is opened or processed. Because the CVSS 4.0 vector indicates a local attack requiring user interaction, victims are typically infected by extracting or previewing a malicious archive received via phishing, a malicious download, or another delivery channel. A successful attacker gains the privileges of the user running WinRAR, providing an initial foothold that has been used for both espionage and ransomware operations. Anyone running the Windows version of WinRAR — one of the most widely deployed Windows desktop utilities — is affected, and CPE data additionally lists dtSearch as an affected vendor. Exploitation is confirmed in the wild by nation-state actors (e.g., the China-linked Amaranth-Dragon group per related reporting) and criminal actors including ransomware operators; the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-12 and carries a near-maximal 94.6% EPSS score.

Do: Update WinRAR to the latest patched release from RARLAB on all Windows endpoints, prioritizing remediation per CISA KEV and BOD 22-01 requirements, and verify that dtSearch deployments bundling the affected component are also updated. Because exploitation requires a user to open or extract a crafted archive, warn users to treat unexpected archive files delivered by email or download with suspicion. Given confirmed ransomware use, hunt across user workstations — not just exposed servers — for suspicious archive-based infections and confirm the patched WinRAR version is installed.

8.495% KEV ransomware
  • RARLAB WinRAR
  • dtsearch
masshundreds of millions of Windows users/devices (est.; RARLAB has historically claimed user counts in the hundreds of millions)
Full article360 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Internet Explorer, Microsoft Office Excel, and WinRAR flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Microsoft Internet Explorer, Microsoft Office Excel, and WinRAR flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the descriptions for these flaws:

  • CVE-2013-3893 Microsoft Internet Explorer Resource Management Errors Vulnerability
  • CVE-2007-0671 Microsoft Office Excel Remote Code Execution Vulnerability
  • CVE-2025-8088 RARLAB WinRAR Path Traversal Vulnerability
  • CVE-2013-3893 – The flaw is a use-after-free issue in mshtml.dll’s SetMouseCapture in IE 6–11 that lets remote attackers run arbitrary code via crafted JavaScript, such as an ms-help: URL loading hxds.dll.. In September 2013, security experts at FireEye uncovered the Operation DeputyDog against Japanese entities that exploited the zero-day CVE-2013-3893.
  • CVE-2007-0671 – The flaw is an unspecified issue in Microsoft Excel 2000, XP, 2003, and 2004 for Mac that could let remote, user-assisted attackers execute code, as seen in zero-day attacks.
  • CVE-2025-8088 – The WinRAR flaw CVE-2025-8088 is a directory traversal bug fixed in version 7.13 that was exploited as a zero-day in phishing attacks to deliver RomCom malware, Bleeping Computer first reported. The flaw is a path traversal vulnerability affecting the Windows version of WinRAR. Attackers can exploit the vulnerability to execute arbitrary code by crafting malicious archive files. Researchers Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET disclosed the flaw. Attackers can craft archives that place executables in Windows Startup folders, causing them to run at login and enabling remote code execution. ESET researchers told Bleeping Computer that threat actors actively exploited the vulnerability in spear-phishing attacks to deliver RomCom backdoors.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by September 2, 2025.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, cisa)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/181110/hacking/u-s-cisa-adds-microsoft-internet-explorer-microsoft-office-excel-and-winrar-flaws-to-its-known-exploited-vulnerabilities-catalog.html