#1 out of 2167.22%
technology1h ago
An almost two-decade-old Excel vulnerability is being actively exploited by bad actors
Pcgamer.com and 1 more
- CISA flags CVE-2009-0238 as actively exploited, urging patching by April 28.
- The exploit enables remote code execution via a crafted Excel file.
- Severity is rated 8.8/10, signaling serious potential impact.
- Patch history shows the flaw was addressed long ago, yet some systems remain unpatched.
- CISA also warns of a new Office 365 spoofing exploit that is automatable.
- CISA links the Excel flaw to Trojan.Mdropper.AC malware in early reported campaigns.
- The advisory covers several Excel versions on Windows and Mac platforms.
- CISA updates KEV catalog with active exploits to guide organizations.
- The risk extends to phishing and weaponized spreadsheets used in attacks.
- The stories emphasize continuing legacy vulnerabilities despite patches.
Vote 1







