CVE-2007-0671
published 2007-02-03CVE-2007-0671: Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to…
PriorityP276high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-09-02
Exploited in the wild
EPSS
42.14%
98.5th percentile
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | access | — | — |
| microsoft | access | — | — |
| microsoft | access | — | — |
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | excel_viewer | — | — |
| microsoft | frontpage | — | — |
| microsoft | frontpage | — | — |
| microsoft | frontpage | — | — |
| microsoft | infopath | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | onenote | — | — |
| microsoft | outlook | — | — |
| microsoft | outlook | — | — |
| microsoft | outlook | — | — |
| microsoft | powerpoint | — | — |
| microsoft | powerpoint | — | — |
| microsoft | powerpoint | — | — |
| microsoft | project | — | — |
| microsoft | project | — | — |
| microsoft | project | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Malicious Excel file delivered as email attachment or hosted on a malicious website should be treated as a delivery vector for this RCE vulnerability. ↗
- →Monitor for opening of specially crafted Excel files in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, as this triggers the vulnerability. ↗
- ·The exact attack vectors are unspecified; detection must rely on behavioral and file-based indicators rather than a known exploit signature. ↗
- ·Scope of affected products may extend beyond Excel to other Office products, broadening the attack surface. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Office 2000/2003/2004/Xp Undefined String format string (MS07-015 / VU#613740)
vuldb·2026-04-22·CVSS 8.8
CVE-2007-0671 [HIGH] Microsoft Office 2000/2003/2004/Xp Undefined String format string (MS07-015 / VU#613740)
A vulnerability identified as critical has been detected in Microsoft Office 2000/2003/2004/Xp. Affected by this vulnerability is an unknown functionality of the component Undefined String Handler. This manipulation causes format string.
This vulnerability appears as CVE-2007-0671. The attack may be initiated remotely. In addition, an exploit is available.
GHSA
GHSA-h24h-phxr-rg3x: Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attacke
ghsa_unreviewed·2022-05-01
CVE-2007-0671 [HIGH] GHSA-h24h-phxr-rg3x: Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attacke
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
VulnCheck
Microsoft Office Excel Remote Code Execution Vulnerability
vulncheck·2007·CVSS 8.8
CVE-2007-0671 [HIGH] Microsoft Office Excel Remote Code Execution Vulnerability
Microsoft Office Excel Remote Code Execution Vulnerability
Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment or hosted on a malicious website. An attacker could leverage this vulnerability by creating a specially crafted Excel file, which, when opened, allowing an attacker to execute remote code on the affected system.
Affected: Microsoft Office
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://cybersecurity.att.com/blogs/labs-research/new-sykipot-developments; https://www.r
CISA
Microsoft Office Excel Remote Code Execution Vulnerability
cisa·2025-08-12·CVSS 8.8
CVE-2007-0671 [HIGH] Microsoft Office Excel Remote Code Execution Vulnerability
Vulnerability: Microsoft Office Excel Remote Code Execution Vulnerability
Affected: Microsoft Office
Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment or hosted on a malicious website. An attacker could leverage this vulnerability by creating a specially crafted Excel file, which, when opened, allowing an attacker to execute remote code on the affected system.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-015 ; https://
No detection rules found.
No public exploits indexed.
Recorded Future
China's Influence on National Network Vulnerability Publications | Recorded Future
blogs_recorded_future·CVSS 7.8
[HIGH] China's Influence on National Network Vulnerability Publications | Recorded Future
## China’s Ministry of State Security Likely Influences National Network Vulnerability Publications
## Executive Summary
Earlier research based on the last two years of vulnerability reporting illustrated that China’s National Vulnerability Database of Information Security (CNNVD) was generally more aggressive in capturing up-to-date information for software vulnerabilities than its U.S. counterpart (NVD). In this research we examine exceptions to this general rule and discover a broader role for the Ministry of State Security (MSS) in vulnerability reporting than was previously known.
Recorded Future analysis has uncovered evidence of a formal vulnerability evaluation process at CNNVD in which High-threat CVEs are likely evaluated for their operational utility by the MSS before publica
Recorded Future
August 2025 CVE Landscape
blogs_recorded_future·CVSS 8.8
[HIGH] August 2025 CVE Landscape
# August 2025 CVE Landscape
In August 2025, Recorded Future’s Insikt Group® identified eighteen high-impact vulnerabilities that should be prioritized for remediation. This represents a decrease from the 22 identified in July.
However, the number of Very Critical vulnerabilities has remained the same (16) compared to July. These vulnerabilities have affected the following vendors: Trend Micro, WinRAR, N-able, Cisco, Apple, Citrix, FreePBX, Git, Microsoft, D-Link, and Fortinet.
August was dominated by Citrix and D-Link flaws, which represented six of the eighteen vulnerabilities. Threat actors actively exploited Citrix NetScaler ADC, NetScaler Gateway, and Citrix Session Recording products, as well as D-Link DNR-322L and DCS-2530L routers.
Recorded Future Insikt Group’s CVE Findings fro
Recorded Future
August 2025 CVE Landscape
blogs_recorded_future·CVSS 8.8
[HIGH] August 2025 CVE Landscape
## August 2025 CVE Landscape
In August 2025, Recorded Future’s Insikt Group ® identified eighteen high-impact vulnerabilities that should be prioritized for remediation. This represents a decrease from the 22 identified in July.
However, the number of Very Critical vulnerabilities has remained the same (16) compared to July. These vulnerabilities have affected the following vendors: Trend Micro, WinRAR, N-able, Cisco, Apple, Citrix, FreePBX, Git, Microsoft, D-Link, and Fortinet.
August was dominated by Citrix and D-Link flaws, which represented six of the eighteen vulnerabilities. Threat actors actively exploited Citrix NetScaler ADC, NetScaler Gateway, and Citrix Session Recording products, as well as D-Link DNR-322L and DCS-2530L routers.
Recorded Future Insikt Group’s CVE Findings f
Recorded Future
China's Influence on National Network Vulnerability Publications
blogs_recorded_future·CVSS 7.8
[HIGH] China's Influence on National Network Vulnerability Publications
# China’s Ministry of State Security Likely Influences National Network Vulnerability Publications
Click here to download the complete analysis as a PDF.
### Executive Summary
Earlier research based on the last two years of vulnerability reporting illustrated that China’s National Vulnerability Database of Information Security (CNNVD) was generally more aggressive in capturing up-to-date information for software vulnerabilities than its U.S. counterpart (NVD). In this research we examine exceptions to this general rule and discover a broader role for the Ministry of State Security (MSS) in vulnerability reporting than was previously known.
Recorded Future analysis has uncovered evidence of a formal vulnerability evaluation process at CNNVD in which High-threat CVEs are likely evaluated
Bugzilla
CVE-2007-1217 Kernel: CAPI overflow
bugzilla·2007-11-28·CVSS 6.9
CVE-2007-1217 [MEDIUM] CVE-2007-1217 Kernel: CAPI overflow
CVE-2007-1217 Kernel: CAPI overflow
Description of problem:
Buffer overflow in the bufprint function in capiutil.c in libcapi, as used in
Linux kernel 2.6.9 to 2.6.20 and isdn4k-utils, allows local users to cause a
denial of service (crash) and possibly gain privileges via a crafted CAPI
packet.
This issue public via:
http://bugs.gentoo.org/show_bug.cgi?id=170867
The reporter (Sune Kloppenborg Jeppesen ) did not attach
a patch :o(.
Discussion:
This was addressed via:
Red Hat Enterprise Linux version 3 (RHSA-2007:0671)
Red Hat Enterprise Linux version 2.1 (RHSA-2007:0672)
Red Hat Linux Advanced Workstation 2.1 (RHSA-2007:0673)
Red Hat Enterprise Linux version 5 (RHSA-2007:0705)
Red Hat Enterprise Linux version 4 (RHSA-2007:0774)
http://osvdb.org/31901http://secunia.com/advisories/24008http://securitytracker.com/id?1017584http://vil.nai.com/vil/content/v_141393.htmhttp://www.avertlabs.com/research/blog/?p=191http://www.kb.cert.org/vuls/id/613740http://www.microsoft.com/technet/security/advisory/932553.mspxhttp://www.securityfocus.com/bid/22383http://www.us-cert.gov/cas/techalerts/TA07-044A.htmlhttp://www.vupen.com/english/advisories/2007/0463https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-015https://exchange.xforce.ibmcloud.com/vulnerabilities/32178https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A301http://osvdb.org/31901http://secunia.com/advisories/24008http://securitytracker.com/id?1017584http://vil.nai.com/vil/content/v_141393.htmhttp://www.avertlabs.com/research/blog/?p=191http://www.kb.cert.org/vuls/id/613740http://www.microsoft.com/technet/security/advisory/932553.mspxhttp://www.securityfocus.com/bid/22383http://www.us-cert.gov/cas/techalerts/TA07-044A.htmlhttp://www.vupen.com/english/advisories/2007/0463https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-015https://exchange.xforce.ibmcloud.com/vulnerabilities/32178https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A301https://learn.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-015https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2007-0671
2007-02-03
Published
2025-08-12
Added to CISA KEV
Exploited in the wild