Vulnerabilities & Exploits

Old Excel RCE Returns to CISA’s Exploited List

A 17-year-old Excel flaw is back in active use, and the standard response of treating it as legacy risk misses the point: old document bugs still let attackers turn trusted files into code execution and phishing bait. Once a victim opens the file, the trust signal is already working for the attacker.

CISA added CVE-2009-0238 to its Known Exploited Vulnerabilities catalog after confirming active exploitation and gave federal civilian agencies two weeks to patch. Microsoft says the issue affects Excel 2000 SP3, 2002 SP3, 2003 SP3, 2007 SP1, Excel Viewer 2003 Gold and SP3, Excel Viewer, the Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1, and Excel for Mac 2004 and 2008.

The forward risk is not just code execution on old installs. The flaw can also help attackers spoof trusted content, which makes malicious documents harder to spot when defenders rely on metadata or file appearance.

1 source · Apr 15

CVE-2009-0238

NVD KEV

Known exploited · CISA KEV

CVSS 8.8 HIGH: microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer… EPSS 43% (99th percentile).

CISA federal remediation date Apr 28

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-04-15

Every edition of this story: Old Excel RCE Returns to CISA’s Exploited List

More from today