Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC.
Is CVE-2009-0238 exploited?
Listed in the CISA KEV catalog on 2026-04-14.
Federal remediation due 2026-04-28.
Past that date by 109 days.
EPSS puts exploitation in the next 30 days at 43%.
Public exploit code: none found in monitored sources.