CVE-2007-0671 Details
Description
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
A remote code execution vulnerability has been identified in multiple Microsoft Office products, including Excel 2000, XP, 2003, and 2004 for Mac. This vulnerability allows remote user-assisted attackers to execute arbitrary code by exploiting a flaw in how Excel parses specially crafted files, leading to memory corruption. The issue has been observed in targeted zero-day attacks.
Users can apply the security update for this vulnerability through the Microsoft Update service. Detailed instructions for downloading and installing the update are available on the Microsoft Update Catalog page for this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Microsoft Office Excel Remote Code Execution Vulnerability | Aug 12, 2025 | Sep 2, 2025 | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft access | 2000 2002 2003 |
CPE
Remediation
| |
| microsoft excel | 2000 2002 2003 |
CPE
Remediation
| |
| microsoft excel viewer | 2003 |
CPE
Remediation
| |
| microsoft frontpage | 2000 2002 2003 |
CPE
Remediation
| |
| microsoft infopath | 2003 |
CPE
Remediation
| |
| microsoft office | 2000 sp3 2003 sp2 2004 xp sp3 |
CPE
Remediation
| |
| microsoft onenote | 2003 |
CPE
Remediation
| |
| microsoft outlook | 2000 2002 2003 |
CPE
Remediation
| |
| microsoft powerpoint | 2000 2002 2003 |
CPE
Remediation
| |
| microsoft project | 2000 sr1 2002 sp1 2003 |
CPE
Remediation
| |
| microsoft publisher | 2000 2002 2003 |
CPE
Remediation
| |
| microsoft visio | 2002 sp2 2003 |
CPE
Remediation
| |
| microsoft word | 2000 2002 2003 |
CPE
Remediation
| |
| microsoft word viewer | 2003 |
CPE
Remediation
| |
Change History
14 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Jun 16, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2026 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Aug 13, 2025 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Aug 12, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 12, 2018 | CVE Modified | [email protected] |
| Oct 11, 2017 | CVE Modified | [email protected] |
| Jul 29, 2017 | CVE Modified | [email protected] |
| Feb 5, 2007 | Initial Analysis | [email protected] |