CVE-2007-0671
Microsoft Office Excel Remote Code Execution Vulnerability
Description
CVE-2007-0671 is a high-severity vulnerability in Microsoft Office products, specifically affecting Excel 2000, XP, 2003, and 2004 for Mac. The vulnerability allows remote attackers to execute arbitrary code through crafted Excel files that exploit an unspecified flaw in the application. With a CVSS v3.1 score of 8.8, this vulnerability was used in targeted zero-day attacks before Microsoft released a security bulletin. CISA has added CVE-2007-0671 to the Known Exploited Vulnerabilities catalog with a remediation deadline of September 2, 2025, and its EPSS score of 69.19% at the 98th percentile reflects extremely high exploitation probability, consistent with its long history as a weaponized vulnerability.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| microsoft | access | 2000; 2002; 2003 |
| microsoft | excel | 2000; 2002; 2003 |
| microsoft | excel viewer | 2003 |
| microsoft | frontpage | 2000; 2002; 2003 |
| microsoft | infopath | 2003 |
| microsoft | office | 2000; 2003; 2004; xp |
| microsoft | onenote | 2003 |
| microsoft | outlook | 2000; 2002; 2003 |
| microsoft | powerpoint | 2000; 2002; 2003 |
| microsoft | project | 2000; 2002; 2003 |
| microsoft | publisher | 2000; 2002; 2003 |
| microsoft | visio | 2002; 2003 |
| microsoft | word | 2000; 2002; 2003 |
| microsoft | word viewer | 2003 |
References
- http://osvdb.org/31901(Broken Link)
- http://secunia.com/advisories/24008(Broken Link, Vendor Advisory)
- http://securitytracker.com/id?1017584(Broken Link)
- http://vil.nai.com/vil/content/v_141393.htm(Broken Link)
- http://www.avertlabs.com/research/blog/?p=191(Broken Link)
- http://www.kb.cert.org/vuls/id/613740(US Government Resource)
- http://www.microsoft.com/technet/security/advisory/932553.mspx(Broken Link, Vendor Advisory)
- http://www.securityfocus.com/bid/22383(Broken Link)
- http://www.us-cert.gov/cas/techalerts/TA07-044A.html(Broken Link, US Government Resource)
- http://www.vupen.com/english/advisories/2007/0463(Vendor Advisory)
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-015(Vendor Advisory)
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32178(Third Party Advisory)
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A301(Broken Link)
- https://learn.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-015(Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2007-0671(US Government Resource)
Weakness Type
This vulnerability does not have a specific CWE classification assigned. The exact technical mechanism was not publicly disclosed in detail by Microsoft, though it was demonstrated through the Exploit-MSExcel.h proof of concept in targeted zero-day attacks against specific organizations. The vulnerability resides in how Microsoft Excel processes certain file structures, allowing memory corruption that leads to arbitrary code execution.
Impact Analysis
CVE-2007-0671 enables remote code execution through a network-delivered attack (AV:N) with low complexity (AC:L), requiring no privileges (PR:N) but needing user interaction (UI:R) to open the malicious Excel file. Confidentiality (High): successful exploitation gives the attacker access to all data accessible to the user, including documents, email, and network resources. Integrity (High): the attacker can install malware, modify files, and establish persistent access on the compromised system. Availability (High): the attacker can render the system unusable through ransomware, data destruction, or resource exhaustion. The wide deployment of Microsoft Office across corporate and government environments made this vulnerability particularly dangerous at the time of its discovery, and the EPSS score of 69.19% at the 98th percentile confirms it remains one of the most exploited vulnerabilities ever cataloged. Multiple Office products are affected including Excel, Word, PowerPoint, Outlook, Access, FrontPage, Publisher, Project, Visio, and OneNote.
Exploit Maturity
CVE-2007-0671 has an extremely mature exploit landscape. Public exploit code is available as demonstrated by the Exploit-MSExcel.h payload used in the original targeted zero-day attacks. CISA has confirmed active exploitation by adding it to the KEV catalog. The EPSS score of 69.19% at the 98th percentile indicates near-certain exploitation activity, placing it among the top 2% of all vulnerabilities. Microsoft published Security Advisory 932553 and subsequently addressed the vulnerability in MS07-015. Although this vulnerability dates to 2007, its continued presence in the KEV catalog highlights that unpatched legacy Office installations remain targets for exploitation.
Remediation
-
Apply Microsoft Security Bulletin MS07-015 which addresses CVE-2007-0671. The bulletin is available at MS07-015 and provides patches for all affected Office versions.
-
Upgrade legacy Microsoft Office installations to currently supported versions. Office 2000, XP, 2003, and 2004 for Mac are long past end of life and no longer receive security updates. Migration to Microsoft 365 or Office 2021+ eliminates this and many other historical vulnerabilities.
-
Implement email attachment filtering to block or quarantine Excel files from untrusted sources. Configure email gateways to sandbox suspicious Office documents and inspect them for known exploit patterns before delivery to end users.
-
Enable Protected View and Application Guard in modern Office versions, which open documents from untrusted sources in a sandboxed environment that prevents code execution even if an exploit is triggered.
-
Audit the environment for legacy Office installations that may still be running on overlooked systems, virtual machines, or terminal servers. Any system running Office 2003 or earlier should be treated as a high-priority risk requiring immediate remediation or decommissioning.
Technical Details
CVE-2007-0671 is an unspecified code execution vulnerability in Microsoft Excel and other Office products. The CVSS v3.1 vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H indicates a network-delivered attack requiring user interaction (opening a malicious file) with high impact across all CIA dimensions. The exact vulnerability mechanism was not fully disclosed, but the attack involves crafting a malicious Excel file that triggers memory corruption when processed by the application. The Exploit-MSExcel.h proof of concept demonstrated that specially constructed spreadsheet data could hijack program control flow and execute attacker-supplied code. The scope of affected products extends beyond Excel to include Word, PowerPoint, Access, FrontPage, InfoPath, OneNote, Outlook, Publisher, Project, Visio, and their respective viewers, suggesting the vulnerability resides in a shared Office component. Microsoft addressed the issue in the February 2007 security bulletin cycle through MS07-015.
Frequently Asked Questions
Is CVE-2007-0671 being actively exploited?
Yes. CVE-2007-0671 was originally used in targeted zero-day attacks and has been added to CISA's KEV catalog. The EPSS score of 69.19% at the 98th percentile indicates extremely high exploitation probability, reflecting continued targeting of unpatched legacy Office installations.
What products are affected by CVE-2007-0671?
Microsoft Office 2000, XP, 2003, and Office 2004 for Mac are affected, including Excel, Word, PowerPoint, Outlook, Access, FrontPage, Publisher, Project, Visio, OneNote, InfoPath, and their viewer applications.
How do I fix CVE-2007-0671?
Apply Microsoft Security Bulletin MS07-015 or, preferably, upgrade to a currently supported version of Microsoft Office. Legacy Office versions are no longer supported and should be replaced with modern alternatives.
How severe is CVE-2007-0671?
CVE-2007-0671 has a CVSS v3.1 score of 8.8 (High severity). It enables remote code execution through malicious Office documents, and its 98th percentile EPSS score makes it one of the most exploited vulnerabilities in the catalog.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.