CVE-2009-0238
published 2009-02-25CVE-2009-0238: Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and…
PriorityP181high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-04-28
Exploited in the wild
EPSS
43.06%
98.6th percentile
Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office_compatibility_pack | — | — |
| microsoft | office_excel_viewer | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect opening of a specially crafted Excel file containing a malformed/invalid object, which triggers the CVE-2009-0238 code execution path. ↗
- →The exploit triggers when Excel attempts to process a document with an invalid object — monitor Excel process for anomalous child process spawning or memory access violations on document open. ↗
- →Snort/VRT rules were released on 2009-02-27 specifically covering CVE-2009-0238 exploitation; reference the VRT advisory for applicable rule SIDs. ↗
- ·Affected products span multiple Excel versions and platforms; ensure detection/patching coverage includes all listed variants. ↗
- ·CISA KEV remediation deadline was April 28, 2026 for FCEB agencies — patch per MS09-009 or discontinue use if mitigations are unavailable. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck9.3CRITICAL
cisa9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Microsoft Office Remote Code Execution
cisa·2026-04-14·CVSS 9.3
CVE-2009-0238 [CRITICAL] CWE-94 Microsoft Office Remote Code Execution
Vulnerability: Microsoft Office Remote Code Execution
Affected: Microsoft Office
Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-009 ; https://nvd.nist.gov/vuln/detail/CVE-2009-0238
Remediation Due Date: 2026-04-28
VulDB
Microsoft Excel 2000/2002/2003/2004/2007 Object Reference code injection (Nessus ID 900476 / ID 110093)
vuldb·2026-04-15·CVSS 9.3
CVE-2009-0238 [CRITICAL] Microsoft Excel 2000/2002/2003/2004/2007 Object Reference code injection (Nessus ID 900476 / ID 110093)
A vulnerability marked as critical has been reported in Microsoft Excel 2000/2002/2003/2004/2007. This issue affects some unknown processing of the component Object Reference Handler. This manipulation causes code injection.
This vulnerability is handled as CVE-2009-0238. The attack can be initiated remotely. Additionally, an exploit exists.
GHSA
GHSA-qw7j-w352-g8m7: Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, a
ghsa_unreviewed·2022-05-02
CVE-2009-0238 [HIGH] CWE-94 GHSA-qw7j-w352-g8m7: Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, a
Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC.
VulnCheck
Microsoft Excel Improper Control of Generation of Code ('Code Injection')
vulncheck·2009·CVSS 9.3
CVE-2009-0238 [CRITICAL] Microsoft Excel Improper Control of Generation of Code ('Code Injection')
Microsoft Excel Improper Control of Generation of Code ('Code Injection')
Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC.
Affected: Microsoft Excel
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.cve.org/CVERecord?id=CVE-2009-0238; https://learn.microsoft.com/en-
No detection rules found.
No public exploits indexed.
Hackernews
ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More Stories
blogs_hackernews·2026-04-16
ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More Stories
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More Stories
You know that feeling when you open your feed on a Thursday morning and it's just... a lot? Yeah. This week delivered. We've got hackers getting creative in ways that are almost impressive if you ignore the whole "crime" part, ancient vulnerabilities somehow still ruining people's days, and enough supply chain drama to fill a season of television nobody asked for.
Not all bad though. Some threat actors got exposed with receipts, a few platforms finally tightened things up, and there's research in here that's genuinely worth
Talos
Rule release for today - February 27th 2009
blogs_talos·2009-02-27·CVSS 9.3
CVE-2009-0238 [CRITICAL] Rule release for today - February 27th 2009
We've been busy again...
Microsoft Excel Code Execution (CVE-2009-0238):
Microsoft Excel contains a programming error that may allow a remote attacker to execute code on a vulnerable system. The problem occurs when Excel attempts to process a specially crafted document with an invalid object.
This issue is being actively exploited by Trojan.Mdropper.AC.
Details are available here: http://www.snort.org/vrt/advisories/vrt-rules-2009-02-27.html
Talos
Rule release for today - February 27th 2009
blogs_talos·2009-02-27·CVSS 9.3
CVE-2009-0238 [CRITICAL] Rule release for today - February 27th 2009
## Rule release for today - February 27th 2009
We've been busy again...
Microsoft Excel Code Execution (CVE-2009-0238): Microsoft Excel contains a programming error that may allow a remote attacker to execute code on a vulnerable system. The problem occurs when Excel attempts to process a specially crafted document with an invalid object.
This issue is being actively exploited by Trojan.Mdropper.AC.
Details are available here: http://www.snort.org/vrt/advisories/vrt-rules-2009-02-27.html
http://blogs.zdnet.com/security/?p=2658http://isc.sans.org/diary.html?storyid=5923http://securitytracker.com/id?1021744http://www.microsoft.com/technet/security/advisory/968272.mspxhttp://www.securityfocus.com/bid/33870http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-022310-4202-99http://www.us-cert.gov/cas/techalerts/TA09-104A.htmlhttp://www.vupen.com/english/advisories/2009/1023https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-009https://exchange.xforce.ibmcloud.com/vulnerabilities/48875https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5968http://blogs.zdnet.com/security/?p=2658http://isc.sans.org/diary.html?storyid=5923http://securitytracker.com/id?1021744http://www.microsoft.com/technet/security/advisory/968272.mspxhttp://www.securityfocus.com/bid/33870http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-022310-4202-99http://www.us-cert.gov/cas/techalerts/TA09-104A.htmlhttp://www.vupen.com/english/advisories/2009/1023https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-009https://exchange.xforce.ibmcloud.com/vulnerabilities/48875https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5968https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-0238
2009-02-25
Published
2026-04-14
Added to CISA KEV
Exploited in the wild