Skip to main content

CVE-2007-0671

8.8
HIGHCVSS v3.1 Base Score
52.33%
MEDIUM RiskEPSS (98th percentile)
KEV
NVD-CWE-noinfo

Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.

Published: 2/3/2007
Modified: 4/22/2026
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Microsoft Office Excel Remote Code Execution Vulnerability

Vendor / Product:

Microsoft Office

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Due Date: 9/2/2025(OVERDUE)
Added to KEV:

8/12/2025

Notes:

https://learn.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-015 ; https://nvd.nist.gov/vuln/detail/CVE-2007-0671

Vulnerability Summary

CVSS v3 Score

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2 Score

9.3

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

52.33%MEDIUM Exploitation Risk
98th percentile

This vulnerability has a 52.33% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.

CWE Classification

NVD-CWE-noinfo

Related Vulnerabilities