CVE-2009-0238Active Exploitation(microsoft / excel)

CRITICALCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 11 mentions and remains active

Immediate actions

  • Patch microsoft excel systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-28. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-94

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • excel
  • excel_viewer
  • office
  • office_compatibility_pack

Threat summary

  • Active exploitation appears in 24 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 27 mentions across 7 observed days

What's happening

  • Active exploitation reported across 24 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 14 signals
  • General: 1 classified signal
  • Peaked 6d ago at 11 mentions (2026-04-14); latest day: 6
  • 27 total mentions across 7 days

Affected systems

Vendors
Products
excelexcel_viewerofficeoffice_compatibility_packoffice_excel_viewer

6 versions affected across 5 products

Deep dive

Activity timeline27 mentions / 7d
036811Mentions · 2026-04-14: 11Mentions · 2026-04-15: 4Mentions · 2026-04-16: 2Mentions · 2026-04-19: 1Mentions · 2026-04-20: 1Mentions · 2026-04-21: 2Mentions · 2026-05-01: 6PoC Mentioned / Linked · 2026-04-15: 1PoC Mentioned / Linked · 2026-05-01: 1Exploit Tool / Code · 2026-04-15: 1Exploit Tool / Code · 2026-05-01: 1Active Exploitation · 2026-04-14: 9Active Exploitation · 2026-04-15: 4Active Exploitation · 2026-04-16: 2Active Exploitation · 2026-04-19: 1Active Exploitation · 2026-04-21: 2Active Exploitation · 2026-05-01: 6Patch / Workaround · 2026-04-14: 3Patch / Workaround · 2026-04-15: 3Patch / Workaround · 2026-04-16: 1Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-05-01: 1Technical Details · 2026-04-14: 8Technical Details · 2026-04-15: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-20: 1Technical Details · 2026-04-21: 204-1404-1504-1604-1904-2004-2105-01
Signal classification3 categories
Active Exploitation
2488.9%
Patch
27.4%
General
13.7%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-04-1411
Active Exploitation9Patch2
2026-04-154
Active Exploitation4
2026-04-162
Active Exploitation2
2026-04-191
Active Exploitation1
2026-04-201
General1
2026-04-212
Active Exploitation2
2026-05-016
Active Exploitation6
Full discourse20 posts
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Microsoft Office remote code execution vulnerability CVE-2009-0238 & Microsoft SharePoint server improper input validation vulnerability CVE-2026-32201 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q for more information. https://t.co/U1Ff9SUWOz

    Post summary

    The tweet announces two CVEs as part of a catalog of known exploited vulnerabilities, indicating they are actively exploited in the wild, though no exploit code or patch information is shared.

    7314671716.9K
    299.0K followersView on X
  • mRr3b00t@UK_Daniel_Card
    Active Exploitation

    CVE-2009-0238 is now in KEV! 2009 is back baby!

    Post summary

    CVE-2009-0238 has been added to the CISA KEV list, indicating it is actively exploited in the wild; no PoC, exploit code, patch, or technical details are provided.

    4513737.0K
    123.1K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(4/14追加) 🛡️No.1568 CVE-2009-0238 Microsoft Office Remote Code Execution Vulnerability ==================================== ✅概要 ・深刻度:8.8 重要 (CVSS Base) / CISA-ADP ・種別:境界外書き込み (CWE-119) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Microsoft Officeにおいて、メモリ処理の不備に起因する脆弱性が存在。事前認証されていない攻撃者により、細工したOfficeファイルをユーザに開かせることで、メモリ破損を引き起こさせ、ユーザー権限で任意コードを実行される恐れがある。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ✅攻撃前提条件 ・ユーザが細工されたOfficeファイルを開く必要がある ✅悪用時影響 ・任意コード実行 ・情報の取得、改ざん、システム影響 ✅悪用事例等に関する公開情報 ・PoC/Exploit:解析情報等あり ・ITW:確認ずみ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2009-0238 https://learn.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-017 🛡️No.1569 CVE-2026-32201 Microsoft SharePoint Server Improper Input Validation Vulnerability ==================================== ✅概要 ・深刻度:6.5 注意 (CVSS Base) / Microsoft Corporation (CNA) ・種別:入力の検証の不備 (CWE-20) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Microsoft SharePoint Serverにおいて、入力の検証の不備に起因する脆弱性が存在。事前認証されていない攻撃者により、細工されたリクエストを介して、不正な入力を処理される恐れがある。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅攻撃前提条件 ・SharePoint Serverへのネットワークアクセスが可能 ✅悪用時影響 ・情報の取得 ・情報の改ざん ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 --- ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-32201 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32201 https://www.cisa.gov/news-events/alerts/2026/04/14/cisa-adds-two-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA cataloged two vulnerabilities: CVE-2009-0238, with confirmed exploitation and PoC, and CVE-2026-32201, still unconfirmed; vendor patches are referenced for both.

    020755.5K
    43.5K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    CISA adds Microsoft SharePoint spoofing (CVE-2026-32201) and legacy Office RCE (CVE-2009-0238) to its KEV Catalog. Remediation deadline: April 28, 2026. #CISA #KEV #SharePoint #CyberSecurity #InfoSec #PatchNow #MicrosoftOffice https://securityonline.info/cisa-kev-sharepoint-spoofing-legacy-office-rce-alert/ https://t.co/yQO1zfmBHj

    Post summary

    CISA announces that Microsoft SharePoint spoofing (CVE-2026-32201) and legacy Office RCE (CVE-2009-0238) are now in its KEV catalog, with a remediation deadline of April 28, 2026.

    02031488
    12.3K followersView on X
  • Michael Martino@battista212
    Active Exploitation

    CISA added CVE-2009-0238 (Microsoft Office RCE) and CVE-2026-32201 (SharePoint input validation) to Known Exploited Vulnerabilities — both under active exploitation. FCEB agencies hit remediation deadline under BOD 22-01. If you're running either, patch now. #Cybersecurity #InfoSec

    Post summary

    The tweet announces that CVE‑2009‑0238 and CVE‑2026‑32201 are actively exploited and urges immediate patching.

    22020727
    240 followersView on X
  • University of ZERO@zerotalktoai
    Active Exploitation

    CISA Adds Two Known Exploited Vulnerabilities to Catalog 04/14/2026 2:30 PM EST CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2009-0238 Microsoft Office Remote Code Execution Vulnerability CVE-2026-32201 Microsoft SharePoint Server Improper Input Validation Vulnerability

    Post summary

    CISA announces that CVE-2009-0238 and CVE-2026-32201 are under active exploitation, adding them to its Known Exploited Vulnerabilities catalog.

    0104181
    1.6K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:14 UTC: Thread live on @lyrie_ai. What happened CISA has added CVE-2009-0238 to the Known Exploited Vulnerabilities (KEV) catalog, signaling confirmed in-the-wild exploitation and setting a remediation due date of 2026-04-28 CISA KEV.

    Post summary

    CISA has classified CVE-2009-0238 as a known exploited vulnerability, confirming active exploitation in the wild and setting a remediation deadline, though no PoC, exploit code, patch details, or technical specifics are provided.

    2000023
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    03:00 UTC: First exploit attempt in the wild. What happened CISA has added CVE-2009-0238 to the Known Exploited Vulnerabilities (KEV) catalog, signaling confirmed in-the-wild exploitation and setting a remediation due date of 2026-04-28 CISA KEV.

    Post summary

    CISA has listed CVE-2009-0238 as a known exploited vulnerability, confirming real‑world exploitation and establishing a remediation deadline.

    1000032
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:11 UTC: GPT-5 enrichment complete. 778 words. 3 citations. What happened CISA has added CVE-2009-0238 to the Known Exploited Vulnerabilities (KEV) catalog, signaling confirmed in-the-wild exploitation and setting a remediation due date of 2026-04-28 CISA KEV.

    Post summary

    CISA has listed CVE-2009-0238 as a known exploited vulnerability, confirming active in-the-wild attacks and specifying a remediation due date.

    1000022
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:03 UTC: Lyrie Sentinel flagged it. What happened CISA has added CVE-2009-0238 to the Known Exploited Vulnerabilities (KEV) catalog, signaling confirmed in-the-wild exploitation and setting a remediation due date of 2026-04-28 CISA KEV.

    Post summary

    CISA has classified CVE-2009-0238 as a known exploited vulnerability, confirming active in-the-wild exploitation and setting a remediation due date.

    1000020
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:00 UTC: CVE-2009-0238 disclosed. CISA: CVE-2009-0238 added to Known Exploited Vulnerabilities — Microsoft Office What happened CISA has added CVE-2009-0238 to the Known Exploited Vulnerabilities (KEV) catalog, signaling confirmed in-the-wild exploitation and setting a…

    Post summary

    CISA has added CVE-2009-0238 to its Known Exploited Vulnerabilities catalog, indicating this vulnerability is actively exploited in the wild.

    1000033
    152 followersView on X
  • [email protected]@BehroozParhami
    Active Exploitation

    An old Excel bug from 2009 returns to life: A forgotten Microsoft Excel flaw, CVE-2009-0238 (9.3), which is being actively exploited, was added it to its Known Exploited Vulnerability catalog on April 14, 2026, shortly after Microsoft rolled out 165 patches. ... [1/2]

    Post summary

    CVE‑2009‑0238 is an old Microsoft Excel flaw that is actively being exploited in the wild and has recently received 165 patches from Microsoft.

    0010036
    671 followersView on X
  • Cyber Edition@CyberEdition
    Active Exploitation

    ⚠️ CISA flags 2 actively exploited bugs in KEV list: • CVE-2009-0238 (MS Office RCE) • CVE-2026-32201 (SharePoint flaw) Old and new, both in the wild. Patch fast or stay exposed. https://www.cisa.gov/news-events/alerts/2026/04/14/cisa-adds-two-known-exploited-vulnerabilities-catalog #CyberSecurity

    Post summary

    CISA reports two CVEs—CVE‑2009‑0238 (MS Office RCE) and CVE‑2026‑32201 (SharePoint flaw)—as actively exploited, urging organizations to patch immediately.

    00010117
    719 followersView on X
  • Mr.Rabbit@01ra66it
    Active Exploitation

    【17年前のOffice/Excel脆弱性がいま再びKEV入り】 NVD上でCVE-2009-0238が2026/04/14にCISA KEVへ追加され、対応期限は4/28とされています。対象はかなり古いExcel/Office系ですが、ここで重要なのは「古い脆弱性でも、環境に残っていれば現在進行形の攻撃面になる」という点です。 特に、旧形式ファイルを扱う業務、互換性維持のために残された端末、Viewerや互換パック運用は再点検が必要です。パッチ適用だけでなく、旧文書の受領経路、メール添付、開封端末のEDR監視までセットで見直したい局面です。 “古い脆弱性=過去の話”ではなく、“残っている資産=現在のリスク”として扱うべき事例です。 #CVE #KEV #MicrosoftOffice #Excel #VulnerabilityManagement #CyberSecurity https://nvd.nist.gov/vuln/detail/cve-2009-0238

    Post summary

    CVE-2009-0238, a 17‑year‑old Office/Excel flaw, was recently added to the CISA KEV list, indicating it remains exploitable. Organizations are urged to apply the patch before the 28‑April deadline and review legacy document handling to mitigate the current risk.

    00001268
    3.5K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2009-0238-office #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The tweet points to research that documents an actively used exploit for CVE-2009-0238 in Microsoft Office, implying ongoing attacks while no mitigation details are provided.

    0000023
    152 followersView on X
  • Michael Martino@battista212
    Active Exploitation

    CISA added CVE-2009-0238 to KEV catalog - 2009 Microsoft Excel RCE now seeing fresh in-the-wild abuse against legacy Office installs. Also cataloged CVE-2026-32201, a SharePoint Server spoofing zero-day from this week's Patch Tuesday. FCEB agencies have 2-week deadline.

    Post summary

    CISA’s KEV catalog now includes CVE-2009-0238 with observed in‑the‑wild attacks against legacy Office installs, while also adding a newly disclosed SharePoint spoofing CVE from this week's Patch Tuesday.

    0000091
    202 followersView on X
  • Piechur internetów@u115122121
    General

    CVE-2009-0238 Microsoft Office Remote Code Execution Vulnerability

    Post summary

    The text merely lists CVE-2009-0238 with a brief description of a Microsoft Office remote code execution vulnerability, providing no additional details.

    0000034
    1 followersView on X
  • Enigma-Global@EnigmaGlobalSW
    Active Exploitation

    Intel Report [HIGH] - On April 14, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2009-0238, a 17-year-old remote code execution (RCE) vulnerability in Microsoft Excel, to its Known Exploited Vulnerabilities (KEV)... https://www.enigma-global.com/og/report/cve-2009-0238-17-year-old-microsoft-excel-rce-vulnerability-actively-exploited-mo5b7fq8-wy7i

    Post summary

    CISA announces that CVE-2009-0238, a 17‑year‑old RCE flaw in Microsoft Excel, is being actively exploited, adding it to the KEV list.

    0000035
    4 followersView on X
  • Ryan Alex Ng@Truvizy
    Active Exploitation

    @CISACyber the Office one (CVE-2009-0238) being in active exploitation again is a reminder that patching old vulns matters just as much as new ones. attackers know most users never went back to patch a 2009 CVE.

    Post summary

    The tweet confirms that CVE-2009-0238 is currently being exploited in the wild, emphasizing the continued need to patch legacy vulnerabilities.

    0000041
    17 followersView on X
  • Ebryx LLC@Ebryx
    Active Exploitation

    @CISACyber CISA just raised the alarm: CVE-2009-0238 and CVE-2026-32201 are now actively exploited in the wild. Legacy Office files and on-prem SharePoint remain high-value targets in 2026. This proves that “set and forget” systems are liabilities. Patch aggressively. Segment aggressively.

    Post summary

    CISA announces that CVE-2009-0238 and CVE-2026-32201 are being actively exploited in the wild, urging aggressive patching and segmentation.

    00000130
    195 followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftexcel2000--
Appmicrosoftexcel2002--
Appmicrosoftexcel2003--
Appmicrosoftexcel2007--
Appmicrosoftexcel_viewer---
Appmicrosoftoffice2004macos-
Appmicrosoftoffice2008macos-
Appmicrosoftoffice_compatibility_pack2007--
Appmicrosoftoffice_excel_viewer---
Appmicrosoftoffice_excel_viewer2003--

Explore more