CVE-2009-0238

9.5 CISA KEV

Microsoft · Office

A remote code execution vulnerability in Microsoft Office Excel, triggered by a crafted document, allows attackers to execute arbitrary code via memory corruption.

Executive summary

This legacy remote code execution vulnerability in Microsoft Office Excel remains a critical risk due to continued exploitation in modern phishing campaigns.

Vulnerability

The vulnerability is a remote code execution flaw caused by improper handling of invalid objects in Excel documents. Successful exploitation requires a user to open a specially crafted spreadsheet, leading to memory corruption.

Business impact

Despite its age, this vulnerability carries a CVSS score of 9.5, reflecting the severity of arbitrary code execution. Successful exploitation results in a full system compromise, granting attackers the same permissions as the logged-in user. This poses a severe risk of data theft, malware installation, and persistent unauthorized access to sensitive workstations.

Remediation

Immediate Action: Ensure all legacy Microsoft Office and Excel Viewer installations are updated to the versions provided in security bulletin MS09-009 (KB969680, KB969681, or KB969682).

Proactive Monitoring: Monitor endpoint activity for suspicious file launches or unexpected child processes originating from Excel.exe.

Compensating Controls: Use email filtering solutions to block attachments containing malicious macro-enabled or legacy Excel file formats.

Exploitation status

Public Exploit Available: Unknown (no confirmed modern weaponized exploit, though historically exploited).

Analyst recommendation

The continued exploitation of this legacy flaw highlights the danger of maintaining outdated software within a production environment. Organizations should prioritize decommissioning these EOL products or ensuring they are fully patched to mitigate the risk of code execution from malicious documents.

More Microsoft CVEs

Sources