CVE-2009-0238
Known exploited · CISA KEV
CVSS 8.8 HIGH: microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer… EPSS 43% (99th percentile).
CISA federal remediation date Apr 28
Vulnerabilities & Exploits
A 17-year-old Excel flaw is back in active use, and the standard response of treating it as legacy risk misses the point: old document bugs still let attackers turn trusted files into code execution and phishing bait. Once a victim opens the file, the trust signal is already working for the attacker.
CISA added CVE-2009-0238 to its Known Exploited Vulnerabilities catalog after confirming active exploitation and gave federal civilian agencies two weeks to patch. Microsoft says the issue affects Excel 2000 SP3, 2002 SP3, 2003 SP3, 2007 SP1, Excel Viewer 2003 Gold and SP3, Excel Viewer, the Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1, and Excel for Mac 2004 and 2008.
The forward risk is not just code execution on old installs. The flaw can also help attackers spoof trusted content, which makes malicious documents harder to spot when defenders rely on metadata or file appearance.
1 source · Apr 15
Known exploited · CISA KEV
CVSS 8.8 HIGH: microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer… EPSS 43% (99th percentile).
CISA federal remediation date Apr 28
The Register Security
Ancient Excel bug comes out of retirement for active attacks
: Vuln old enough to drive lands on CISA's exploited list
originalPart of the PlainSec briefing for 2026-04-16
Every edition of this story: Old Excel RCE Returns to CISA’s Exploited List