CVE-2009-0238CISA KEV
Microsoft Office Remote Code Execution
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.
- Product
- Office
- Added to KEV
- 14 Apr 2026
- Federal remediation due
- 28 Apr 2026
- Known ransomware use
- Not reported