CVE-2007-0671Active Exploitation(microsoft / access)

MEDIUMCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch microsoft access systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-09-02. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • access
  • excel
  • excel_viewer
  • frontpage

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 1 signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
accessexcelexcel_viewerfrontpageinfopathofficeonenoteoutlookpowerpointproject

5 versions affected across 14 products

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-30: 3Active Exploitation · 2026-04-30: 2Patch / Workaround · 2026-04-30: 104-30
Signal classification2 categories
Active Exploitation
266.7%
General
133.3%
Referenced assets1 URL
By indicator
Full discourse3 posts
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Vendor. CISA added CVE-2007-0671 to the Known Exploited Vulnerabilities (KEV) catalog, signaling confirmed in‑the‑wild exploitation and setting a remediation due date f

    Post summary

    CISA reports that CVE-2007-0671 is actively exploited in the wild, with no PoC, exploit code, or patch details mentioned.

    1000015
    128 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2007-0671. CISA added CVE-2007-0671 to the Known Exploited Vulnerabilities (KEV) catalog, signaling confirmed in‑the‑wild exploitation and setting a remediation due date for affected environments CISA KEV.

    Post summary

    CISA has classified CVE-2007-0671 as a known exploited vulnerability, confirming active in-the-wild exploitation and providing a remediation timeline.

    1000021
    128 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://research.lyrie.ai/research/active-exploit-cve-2007-0671-office #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The tweet simply shares a link that appears to report an active exploit of CVE‑2007‑0671 in Microsoft Office, without providing further details or supporting evidence.

    0000021
    128 followersView on X
CPE platform detail34 entries

34 of 34 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftaccess2000--
Appmicrosoftaccess2002--
Appmicrosoftaccess2003--
Appmicrosoftexcel2000--
Appmicrosoftexcel2002--
Appmicrosoftexcel2003--
Appmicrosoftexcel_viewer2003--
Appmicrosoftfrontpage2000--
Appmicrosoftfrontpage2002--
Appmicrosoftfrontpage2003--
Appmicrosoftinfopath2003--
Appmicrosoftoffice2000--
Appmicrosoftoffice2003--
Appmicrosoftoffice2004macos-
Appmicrosoftofficexp--
Appmicrosoftonenote2003--
Appmicrosoftoutlook2000--
Appmicrosoftoutlook2002--
Appmicrosoftoutlook2003--
Appmicrosoftpowerpoint2000--
Appmicrosoftpowerpoint2002--
Appmicrosoftpowerpoint2003--
Appmicrosoftproject2000--
Appmicrosoftproject2002--
Appmicrosoftproject2003--
Appmicrosoftpublisher2000--
Appmicrosoftpublisher2002--
Appmicrosoftpublisher2003--
Appmicrosoftvisio2002--
Appmicrosoftvisio2003--
Appmicrosoftword2000--
Appmicrosoftword2002--
Appmicrosoftword2003--
Appmicrosoftword_viewer2003--

Explore more