Changeflow GovPing Data Privacy & Cybersecurity CVE-2009-0238: Microsoft Excel Remote Code Exec...
Priority review Notice Added Final

CVE-2009-0238: Microsoft Excel Remote Code Execution Vulnerability

Favicon for www.cisa.gov CISA Known Exploited Vulnerabilities (KEV)
Published
Detected
Email

Summary

CISA added CVE-2009-0238 to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability affects Microsoft Office Excel versions 2000 SP3 through 2007 SP1, Excel Viewer 2003, Compatibility Pack for Office 2007 formats, and Excel for Mac 2004 and 2008. The vulnerability allows remote code execution via crafted Excel documents and was actively exploited in February 2009 by Trojan.Mdropper.AC. CISA's SSVC assessment rates exploitation as active with total technical impact.

What changed

CISA added CVE-2009-0238 to its Known Exploited Vulnerabilities catalog. This CVE, originally from Microsoft Corporation, describes a remote code execution vulnerability in Microsoft Office Excel versions 2000 SP3 through 2007 SP1, Excel Viewer, Compatibility Pack, and Excel for Mac. The vulnerability allows remote attackers to execute arbitrary code through crafted Excel documents that trigger an access attempt on an invalid object. It was exploited in the wild in February 2009 by Trojan.Mdropper.AC. CISA's SSVC evaluation indicates active exploitation with total technical impact.

Federal agencies and critical infrastructure operators should prioritize remediation of this vulnerability. The KEV catalog entry signals CISA's determination that this vulnerability poses significant risk due to active exploitation. Organizations running any affected Microsoft Office Excel versions should apply the MS09-009 security update immediately to prevent potential remote code execution attacks.

What to do next

  1. Apply Microsoft security update MS09-009 immediately
  2. Review Microsoft security advisory 968272 for mitigation guidance
  3. Prioritize patching affected Microsoft Office Excel installations

Archived snapshot

Apr 15, 2026

GovPing captured this document from the original source. If the source has since changed or been removed, this is the text as it existed at that time.

Required CVE Record Information

CNA: Microsoft Corporation

Updated:

2018-10-12

Description

Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC.

Product Status

Learn more Information not provided

References 11 Total

CVE Program

References 11 Total

Authorized Data Publishers

Learn more

CISA-ADP

SSVC and KEV, plus CVSS and CWE if not provided by the CNA.

SSVC 1 Total

Learn more
| Exploitation | Automatable | Technical Impact | Version | Date Accessed |
| --- | --- | --- | --- | --- |
| active | no | total | 2.0.3 | 2026-04-14 |

KEV 1 Total

Learn more
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-0238 (2026-04-14)

CWE 1 Total

Learn more
- CWE-94: CWE-94 Improper Control of Generation of Code ('Code Injection')

CVSS 1 Total

Learn more
| Score | Severity | Version | Vector String |
| --- | --- | --- | --- |
| 8.8 | HIGH | 3.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |

Get daily alerts for CISA Known Exploited Vulnerabilities (KEV)

Daily digest delivered to your inbox.

Free. Unsubscribe anytime.

About this page

What is GovPing?

Every important government, regulator, and court update from around the world. One place. Real-time. Free. Our mission

What's from the agency?

Source document text, dates, docket IDs, and authority are extracted directly from CISA.

What's AI-generated?

The summary, classification, recommended actions, deadlines, and penalty information are AI-generated from the original text and may contain errors. Always verify against the source document.

Last updated

Classification

Agency
CISA
Published
October 12th, 2018
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive
Document ID
CVE-2009-0238

Who this affects

Applies to
Technology companies Government agencies Healthcare providers
Industry sector
5112 Software & Technology
Activity scope
Vulnerability remediation Software patching Security updates
Geographic scope
United States US

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Compliance frameworks
NIST CSF
Topics
Data Privacy Software & Technology

Get alerts for this source

We'll email you when CISA Known Exploited Vulnerabilities (KEV) publishes new changes.

Free. Unsubscribe anytime.

You're subscribed!