cbcvebase.
CVE-2007-0671
published 2007-02-03

CVE-2007-0671: Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to…

PriorityP276high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-09-02
Exploited in the wild
EPSS
42.14%
98.5th percentile
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftaccess
microsoftaccess
microsoftaccess
microsoftexcel
microsoftexcel
microsoftexcel
microsoftexcel_viewer
microsoftfrontpage
microsoftfrontpage
microsoftfrontpage
microsoftinfopath
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice
microsoftonenote
microsoftoutlook
microsoftoutlook
microsoftoutlook
microsoftpowerpoint
microsoftpowerpoint
microsoftpowerpoint
microsoftproject
microsoftproject
microsoftproject

Detection & IOCsextracted from sources · hover to see the quote

filenameExploit-MSExcel.h
  • Malicious Excel file delivered as email attachment or hosted on a malicious website should be treated as a delivery vector for this RCE vulnerability.
  • Monitor for opening of specially crafted Excel files in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, as this triggers the vulnerability.
  • ·The exact attack vectors are unspecified; detection must rely on behavioral and file-based indicators rather than a known exploit signature.
  • ·Scope of affected products may extend beyond Excel to other Office products, broadening the attack surface.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.