Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
Conclusion & alert: CVE-2007-0671 is rated Critical Active Threat (91.3/100): CVSS High severity, with high exploitation likelihood (EPSS 52.33%, 98th percentile). Core evidence: CISA KEV confirms active exploitation (added 2025-08-12) affecting Microsoft / Office. Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: Microsoft Office Excel Remote Code Execution Vulnerability · CISA KEV detail
: 2025-08-12
: 2025-09-02
: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-31 | 55.49% | 52.33% | -3.16% |
| 2 | 2026-04-23 | 66.80% | 55.49% | -11.32% |
| 3 | 2026-03-05 | — | 66.80% | — |
Full EPSS history (25 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| 9.3 | 2.0 | HIGH |
|
8.6 | 10.0 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2007-0671: no source package rows; 0 state rows across 0 repos (none); fixed 0, open 0. | https://security.alpinelinux.org/vuln/CVE-2007-0671 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| microsoft | access | 2000 | cpe:2.3:a:microsoft:access:2000:*:*:*:*:*:*:* |
| microsoft | access | 2002 | cpe:2.3:a:microsoft:access:2002:*:*:*:*:*:*:* |
| microsoft | access | 2003 | cpe:2.3:a:microsoft:access:2003:*:*:*:*:*:*:* |
| microsoft | excel | 2000 | cpe:2.3:a:microsoft:excel:2000:*:*:*:*:*:*:* |
| microsoft | excel | 2002 | cpe:2.3:a:microsoft:excel:2002:*:*:*:*:*:*:* |
| microsoft | excel | 2003 | cpe:2.3:a:microsoft:excel:2003:*:*:*:*:*:*:* |
| microsoft | excel_viewer | 2003 | cpe:2.3:a:microsoft:excel_viewer:2003:*:*:*:*:*:*:* |
| microsoft | frontpage | 2000 | cpe:2.3:a:microsoft:frontpage:2000:*:*:*:*:*:*:* |
| microsoft | frontpage | 2002 | cpe:2.3:a:microsoft:frontpage:2002:*:*:*:*:*:*:* |
| microsoft | frontpage | 2003 | cpe:2.3:a:microsoft:frontpage:2003:*:*:*:*:*:*:* |
| microsoft | infopath | 2003 | cpe:2.3:a:microsoft:infopath:2003:*:*:*:*:*:*:* |
| microsoft | office | 2000 | cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:* |
| microsoft | office | 2003 | cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:* |
| microsoft | office | 2004 | cpe:2.3:a:microsoft:office:2004:*:*:*:*:macos:*:* |
| microsoft | office | xp | cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:* |
| microsoft | onenote | 2003 | cpe:2.3:a:microsoft:onenote:2003:*:*:*:*:*:*:* |
| microsoft | outlook | 2000 | cpe:2.3:a:microsoft:outlook:2000:*:*:*:*:*:*:* |
| microsoft | outlook | 2002 | cpe:2.3:a:microsoft:outlook:2002:*:*:*:*:*:*:* |
| microsoft | outlook | 2003 | cpe:2.3:a:microsoft:outlook:2003:*:*:*:*:*:*:* |
| microsoft | powerpoint | 2000 | cpe:2.3:a:microsoft:powerpoint:2000:*:*:*:*:*:*:* |
| microsoft | powerpoint | 2002 | cpe:2.3:a:microsoft:powerpoint:2002:*:*:*:*:*:*:* |
| microsoft | powerpoint | 2003 | cpe:2.3:a:microsoft:powerpoint:2003:*:*:*:*:*:*:* |
| microsoft | project | 2000 | cpe:2.3:a:microsoft:project:2000:sr1:*:*:*:*:*:* |
| microsoft | project | 2002 | cpe:2.3:a:microsoft:project:2002:sp1:*:*:*:*:*:* |
| microsoft | project | 2003 | cpe:2.3:a:microsoft:project:2003:*:*:*:*:*:*:* |
| microsoft | publisher | 2000 | cpe:2.3:a:microsoft:publisher:2000:*:*:*:*:*:*:* |
| microsoft | publisher | 2002 | cpe:2.3:a:microsoft:publisher:2002:*:*:*:*:*:*:* |
| microsoft | publisher | 2003 | cpe:2.3:a:microsoft:publisher:2003:*:*:*:*:*:*:* |
| microsoft | visio | 2002 | cpe:2.3:a:microsoft:visio:2002:sp2:*:*:*:*:*:* |
| microsoft | visio | 2003 | cpe:2.3:a:microsoft:visio:2003:*:*:*:*:*:*:* |
| microsoft | word | 2000 | cpe:2.3:a:microsoft:word:2000:*:*:*:*:*:*:* |
| microsoft | word | 2002 | cpe:2.3:a:microsoft:word:2002:*:*:*:*:*:*:* |
| microsoft | word | 2003 | cpe:2.3:a:microsoft:word:2003:*:*:*:*:*:*:* |
| microsoft | word_viewer | 2003 | cpe:2.3:a:microsoft:word_viewer:2003:*:*:*:*:*:*:* |