Junglewise Threat Intelligence

CVE-2007-0671: Microsoft Office Excel remote code execution vulnerability

CVE-2007-0671 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2025-08-12

Technologies: Microsoft Office, Microsoft Excel. Vendors: Microsoft.

Executive brief

Microsoft Excel is a widely used spreadsheet application for data analysis and reporting. A vulnerability in older versions of Excel allows an attacker to take full control of a computer if a user opens a specially crafted malicious spreadsheet. This could lead to the theft of sensitive company data, installation of malware, or complete disruption of business operations.

Technical details

An unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac allows remote attackers to execute arbitrary code. The attack requires user interaction, typically involving a victim opening a maliciously crafted Excel (.xls) file delivered via email or a website. Successful exploitation grants the attacker the same privileges as the logged-in user, potentially leading to full system compromise. This vulnerability has been observed in targeted zero-day attacks. Microsoft has released security bulletin MS07-015 to address this issue.

Affected products

  • Microsoft Excel 2000, XP, 2003, 2004 for Mac
  • Microsoft Office 2000, XP, 2003, 2004 for Mac

Timeline

  • 2007-02-13: advisory: Microsoft released security bulletin MS07-015
  • 2025-08-12: kev added: Added to CISA Known Exploited Vulnerabilities catalog

Related threats