CVE-2007-0671
HIGH(8.8)KEVElevated Risk
Microsoft Office Excel Remote Code Execution Vulnerability
Description
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| microsoft | access | 2000; 2002; 2003 |
| microsoft | excel | 2000; 2002; 2003 |
| microsoft | excel viewer | 2003 |
| microsoft | frontpage | 2000; 2002; 2003 |
| microsoft | infopath | 2003 |
| microsoft | office | 2000; 2003; 2004; xp |
| microsoft | onenote | 2003 |
| microsoft | outlook | 2000; 2002; 2003 |
| microsoft | powerpoint | 2000; 2002; 2003 |
| microsoft | project | 2000; 2002; 2003 |
| microsoft | publisher | 2000; 2002; 2003 |
| microsoft | visio | 2002; 2003 |
| microsoft | word | 2000; 2002; 2003 |
| microsoft | word viewer | 2003 |
References
- http://osvdb.org/31901(Broken Link)
- http://secunia.com/advisories/24008(Broken Link, Vendor Advisory)
- http://securitytracker.com/id?1017584(Broken Link)
- http://vil.nai.com/vil/content/v_141393.htm(Broken Link)
- http://www.avertlabs.com/research/blog/?p=191(Broken Link)
- http://www.kb.cert.org/vuls/id/613740(US Government Resource)
- http://www.microsoft.com/technet/security/advisory/932553.mspx(Broken Link, Vendor Advisory)
- http://www.securityfocus.com/bid/22383(Broken Link)
- http://www.us-cert.gov/cas/techalerts/TA07-044A.html(Broken Link, US Government Resource)
- http://www.vupen.com/english/advisories/2007/0463(Vendor Advisory)
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-015(Vendor Advisory)
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32178(Third Party Advisory)
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A301(Broken Link)
- https://learn.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-015(Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2007-0671(US Government Resource)
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.