Summary
Microsoft Excel in multiple Office versions can mishandle a specially crafted spreadsheet object or record. An attacker can send the malicious file, typically as an email attachment, and if the user opens it in a vulnerable Excel or Viewer version, memory corruption occurs. Successful exploitation executes attacker-controlled code in the context of the user opening the file, and Microsoft said the flaw was being exploited in the Internet ecosystem.
Why Planned Fix?
3/6Exploitation Details
Execute arbitrary code with the privileges of the user opening the file.
RCE (Remote Code Execution)Affected Software
| Product | Affected Versions |
|---|---|
| Microsoft Office Excel 2000 Service Pack 3 | all supported versions |
| Microsoft Office Excel 2002 Service Pack 3 | all supported versions |
| Microsoft Office Excel 2003 Service Pack 3 | all supported versions |
| Microsoft Office Excel 2007 Service Pack 1 | all supported versions |
| Microsoft Office Excel Viewer 2003 | Gold and Service Pack 3 |
| Microsoft Office Excel Viewer | all supported versions |
| Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 1 | all supported versions |
| Microsoft Office 2004 for Mac | all supported versions |
| Microsoft Office 2008 for Mac | all supported versions |
Spreadsheet application used to create, edit, and analyze workbooks and charts.
Affected ComponentExcel workbook/object parser for crafted binary XLS records, including malformed object and SST handling.
Excel workbook/object parser for crafted binary XLS records, including malformed object and SST handling.
Use MOICE to convert untrusted .XLS files before opening them, or block older Office file formats with Office File Block policy.
Use MOICE to convert untrusted .XLS files before opening them, or block older Office file formats with Office File Block policy.
Not available
Apply Microsoft security bulletin MS09-009 / KB968557 to the affected Excel product; Office Excel 2007 SP1 also requires the related Compatibility Pack update KB960003.
Apply Microsoft security bulletin MS09-009 / KB968557 to the affected Excel product; Office Excel 2007 SP1 also requires the related Compatibility Pack update KB960003.
Probability of exploitation in the next 30 days
Worse than 98% of all CVEs
No known threat actors
No detection rules available
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Affected Software (CPE) (11)
- •cpe:2.3:a:microsoft:excel:2004:*:mac:*:*:*:*:*
- •cpe:2.3:a:microsoft:excel_viewer:*:*:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:office:2008:*:mac:*:*:*:*:*
- •cpe:2.3:a:microsoft:office_compatibility_pack:2007:sp1:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:office_excel:2000:sp3:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:office_excel:2002:sp3:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:office_excel:2003:sp3:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:office_excel:2007:sp1:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:office_excel_viewer:*:*:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:office_excel_viewer:2003:gold:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:office_excel_viewer:2003:sp3:*:*:*:*:*:*
Sources
| Source | Article |
|---|---|
| learn.microsoft.com | Microsoft Security Advisory 968272 |
| learn.microsoft.com | Microsoft Security Bulletin MS09-009 |
| learn.microsoft.com | Microsoft Security Bulletin Summary for April 2009 |
| nvd.nist.gov | CVE-2009-0238 Detail |
| www.secureworks.com | Protecting Yourself From Attempts to Exploit CVE-2009-0238 |
| www.microsoft.com | Announcing OffVis 1.0 Beta |
| www.tenable.com | MS09-009: Vulnerabilities in Microsoft Office Excel Could Cause Remote Code Execution |
| www.juniper.net | HTTP: Microsoft Office Excel Crafted SST Record Code Execution |
Priority History
Initial analysis