CVE-2007-0671
critical-risk
Published 2007-02-03
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
Do I need to act?
!
66.8% chance of exploitation in next 30 days
EPSS score — higher than 33% of all CVEs
!
CISA KEV: actively exploited in the wild
On the Known Exploited Vulnerabilities catalog — federal agencies must patch
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.8/10
High
NETWORK
/ LOW complexity
Affected Products (20)
Affected Vendors
References (28)
Vendor Advisory
http://secunia.com/advisories/24008
US Government Resource
http://www.kb.cert.org/vuls/id/613740
Vendor Advisory
http://www.microsoft.com/technet/security/advisory/932553.mspx
US Government Resource
http://www.us-cert.gov/cas/techalerts/TA07-044A.html
Vendor Advisory
http://www.vupen.com/english/advisories/2007/0463
Vendor Advisory
http://secunia.com/advisories/24008
US Government Resource
http://www.kb.cert.org/vuls/id/613740
Vendor Advisory
http://www.microsoft.com/technet/security/advisory/932553.mspx
and 8 more references
79
/ 100
critical-risk
Severity
30/34 · Critical
Exploitability
26/34 · High
Exposure
23/34 · High