Vulnerability record · CVE-2007-0671 · published 3 February 2007
CVE-2007-0671: Microsoft Excel remote code execution via malformed file
Microsoft · Access
CVE-2007-0671 is an unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, that allows remote attackers to execute arbitrary code. The record gives no root-cause detail, but it was demonstrated in targeted zero-day attacks as Exploit-MSExcel.h, so it is a real, weaponized flaw rather than a theoretical one.
Description
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw gives remote code execution with a CVSS 3.1 base of 8.8, was exploited as a zero-day, and is in CISA KEV with a high EPSS score, though it requires user interaction and affects legacy products.
What it is
CVE-2007-0671 is an unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, that allows remote attackers to execute arbitrary code. The record gives no root-cause detail, but it was demonstrated in targeted zero-day attacks as Exploit-MSExcel.h, so it is a real, weaponized flaw rather than a theoretical one.
Impact
An attacker who gets a crafted file opened gains arbitrary code execution in the context of the user running Excel, which can lead to full compromise of the workstation and any credentials or data reachable from it.
Attack surface
Reached remotely by delivering a malicious Excel or other Office file to a victim, who must open it; the CVSS vector shows network attack, no privileges, and required user interaction. No authentication is needed on the attacker side, and the description does not specify the exact parsing path or file format involved.
Exploitation
The flaw was used in targeted zero-day attacks at disclosure and is listed in CISA KEV with a 2025-08-12 addition date, and EPSS gives a 30-day probability of about 0.42 (98.6th percentile), indicating high observed and predicted exploitation activity. No ransomware campaign use is recorded.
What to do
- Apply the Microsoft security update for this issue (MS07-015) or a later cumulative Office update on all affected Excel and Office installations.
- If patching cannot be completed immediately, follow the CISA KEV required action: apply vendor mitigations, apply BOD 22-01 guidance for cloud services, or discontinue use of the affected product.
- Block or strip untrusted Office attachments at the mail and web gateways, and disable automatic opening of files from external sources.
- Retire or isolate end-of-life Excel 2000, XP, 2003, and 2004 for Mac installations that no longer receive security fixes.
- Run Office documents from untrusted sources in a sandbox or with Protected View where the platform supports it.
Detection
- Hunt for Excel or other Office processes spawning child processes such as cmd.exe, powershell.exe, wscript.exe, or rundll32.exe, which is abnormal for document handling.
- Monitor for Office applications loading unusual DLLs or writing executables to temp, startup, or user profile paths shortly after a document is opened.
- Alert on email attachments matching Office file types from external senders that are opened on endpoints running unsupported Excel or Office versions.
- Review proxy and mail logs for known exploit file names or hashes associated with Exploit-MSExcel.h and related samples.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2007-0671 to the Known Exploited Vulnerabilities catalog on 12 August 2025 as "Microsoft Office Excel Remote Code Execution Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 2 September 2025.
Affected products
14 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-0671 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-0671), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.