← Vulnerability feed

Vulnerability record · CVE-2007-0671 · published 3 February 2007

CVE-2007-0671: Microsoft Excel remote code execution via malformed file

Microsoft · Access

CVE-2007-0671 is an unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, that allows remote attackers to execute arbitrary code. The record gives no root-cause detail, but it was demonstrated in targeted zero-day attacks as Exploit-MSExcel.h, so it is a real, weaponized flaw rather than a theoretical one.

8.8 CVSS 3.1 High CISA KEV since 12 Aug 2025 EPSS 43% · top 1.3%
8.8CVSS 3.1 base score, v2 9.3
43%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
14Affected product versions listed by NVD
28References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw gives remote code execution with a CVSS 3.1 base of 8.8, was exploited as a zero-day, and is in CISA KEV with a high EPSS score, though it requires user interaction and affects legacy products.

What it is

CVE-2007-0671 is an unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, that allows remote attackers to execute arbitrary code. The record gives no root-cause detail, but it was demonstrated in targeted zero-day attacks as Exploit-MSExcel.h, so it is a real, weaponized flaw rather than a theoretical one.

Impact

An attacker who gets a crafted file opened gains arbitrary code execution in the context of the user running Excel, which can lead to full compromise of the workstation and any credentials or data reachable from it.

Attack surface

Reached remotely by delivering a malicious Excel or other Office file to a victim, who must open it; the CVSS vector shows network attack, no privileges, and required user interaction. No authentication is needed on the attacker side, and the description does not specify the exact parsing path or file format involved.

Exploitation

The flaw was used in targeted zero-day attacks at disclosure and is listed in CISA KEV with a 2025-08-12 addition date, and EPSS gives a 30-day probability of about 0.42 (98.6th percentile), indicating high observed and predicted exploitation activity. No ransomware campaign use is recorded.

What to do

  • Apply the Microsoft security update for this issue (MS07-015) or a later cumulative Office update on all affected Excel and Office installations.
  • If patching cannot be completed immediately, follow the CISA KEV required action: apply vendor mitigations, apply BOD 22-01 guidance for cloud services, or discontinue use of the affected product.
  • Block or strip untrusted Office attachments at the mail and web gateways, and disable automatic opening of files from external sources.
  • Retire or isolate end-of-life Excel 2000, XP, 2003, and 2004 for Mac installations that no longer receive security fixes.
  • Run Office documents from untrusted sources in a sandbox or with Protected View where the platform supports it.

Detection

  • Hunt for Excel or other Office processes spawning child processes such as cmd.exe, powershell.exe, wscript.exe, or rundll32.exe, which is abnormal for document handling.
  • Monitor for Office applications loading unusual DLLs or writing executables to temp, startup, or user profile paths shortly after a document is opened.
  • Alert on email attachments matching Office file types from external senders that are opened on endpoints running unsupported Excel or Office versions.
  • Review proxy and mail logs for known exploit file names or hashes associated with Exploit-MSExcel.h and related samples.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2007-0671 to the Known Exploited Vulnerabilities catalog on 12 August 2025 as "Microsoft Office Excel Remote Code Execution Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 2 September 2025.

Affected products

14 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://osvdb.org/31901 Broken Link
http://secunia.com/advisories/24008 Broken LinkVendor Advisory
http://securitytracker.com/id?1017584 Broken Link
http://vil.nai.com/vil/content/v_141393.htm Broken Link
http://www.avertlabs.com/research/blog/?p=191 Broken Link
http://www.kb.cert.org/vuls/id/613740 US Government Resource
http://www.microsoft.com/technet/security/advisory/932553.mspx Broken LinkVendor Advisory
http://www.securityfocus.com/bid/22383 Broken Link
http://www.us-cert.gov/cas/techalerts/TA07-044A.html Broken LinkUS Government Resource
http://www.vupen.com/english/advisories/2007/0463 Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-015 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/32178 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A301 Broken Link
http://osvdb.org/31901 Broken Link
http://secunia.com/advisories/24008 Broken LinkVendor Advisory
http://securitytracker.com/id?1017584 Broken Link
http://vil.nai.com/vil/content/v_141393.htm Broken Link
http://www.avertlabs.com/research/blog/?p=191 Broken Link
http://www.kb.cert.org/vuls/id/613740 US Government Resource
http://www.microsoft.com/technet/security/advisory/932553.mspx Broken LinkVendor Advisory
http://www.securityfocus.com/bid/22383 Broken Link
http://www.us-cert.gov/cas/techalerts/TA07-044A.html Broken LinkUS Government Resource
http://www.vupen.com/english/advisories/2007/0463 Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-015 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/32178 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A301 Broken Link
https://learn.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-015 Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2007-0671 US Government Resource

Track CVE-2007-0671 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-1297Microsoft Excel memory handling flaw allows remote code executionCVE-2019-1297 is a remote code execution vulnerability in Microsoft Excel caused by improper handling of objects in memory. An attacker who convinces…KEVEPSS 22%analysed8.8CVE-2019-0541Microsoft MSHTML engine input validation flaw allows remote code executionThe MSHTML engine in Microsoft Office, Internet Explorer and related viewers fails to properly validate input, allowing remote code execution. Becaus…KEVEPSS 53%analysed8.8CVE-2015-2424Microsoft Office memory corruption via crafted documentCVE-2015-2424 is an out-of-bounds write (CWE-787) in Microsoft PowerPoint and Word that is triggered when a crafted Office document is opened. A remo…KEVEPSS 40%analysed8.8CVE-2009-0238Microsoft Excel invalid object access allows remote code executionMicrosoft Excel and related viewers (Excel 2000 through 2007, Excel Viewer, Office Compatibility Pack, and Office for Mac 2004/2008) fail to handle a…KEVEPSS 43%analysed7.8CVE-2021-42292Microsoft Excel security feature bypass via crafted fileCVE-2021-42292 is a security feature bypass in Microsoft Excel and related Office products. The record gives only a one-line description, so the exac…KEVEPSS 43%analysed7.8CVE-2016-7262Microsoft Excel security feature bypass enables command executionA crafted cell in affected Microsoft Excel and Excel Viewer versions is mishandled when a user clicks it, allowing a security feature bypass that lea…KEVEPSS 58%analysed7.8CVE-2013-3906Microsoft GDI+ TIFF parsing code execution via crafted imageGDI+ in multiple Microsoft products fails to properly handle crafted TIFF images, allowing memory corruption that leads to arbitrary code execution. …KEVEPSS 85%analysed7.8CVE-2009-3129Microsoft Excel FEATHEADER record memory corruptionMicrosoft Excel and related Office components mishandle a FEATHEADER record whose cbHdrData size element is invalid, corrupting a pointer offset and …KEVEPSS 84%analysed

Source: NIST National Vulnerability Database (record CVE-2007-0671), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.