← All CVEs

CVE-2007-0028

high · 9.3

Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file, which results in an "Improper Memory Access Vulnerability." NOTE: an early disclosure of this issue used CVE-2006-3432, but only CVE-2007-0028 should be used.

9.3
CVSS
33.2%
EPSS (exploit prob.)
98th
EPSS percentile
2007-01-09
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
microsoftexcel2000
microsoftoffice2000
microsoftexcel2002
microsoftofficexp
microsoftexcel2003
microsoftoffice2003
microsoftexcel_viewer2003
microsoftworks2004
microsoftworks2005
microsoftoffice2004
microsoftofficev.x

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-0028