Executive brief
Microsoft Excel and related Office components contain an object record corruption vulnerability. Remote attackers can execute arbitrary code by tricking a user into opening a specially crafted Excel file containing a malformed record object.
Affected products
- Microsoft Excel 2000 SP3, XP SP3, 2003 SP3, 2007 SP1, 2007 SP2
- Microsoft Excel for Mac 2004, 2008
- Microsoft Office Excel Viewer 2003 SP3, and unversioned
- Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1, SP2
- Microsoft Open XML File Format Converter for Mac
- Microsoft Office SharePoint Server 2007 SP1, SP2
Timeline
- 2009-06-09: patched: Microsoft released security bulletin MS09-021.
- 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2022-06-08: disclosed: NVD publication date.
- exploited: Reported as exploited in the wild.