An old Microsoft Excel security flaw could allow hackers to hijack your entire system, so patch now



  • CISA adds 18-year-old Excel bug (CVE-2009-0238) to KEV catalog
  • Vulnerability enables RCE via malicious Excel files, patched long ago
  • Outdated systems remain at risk; agencies ordered to patch before April 28

Incredibly, there are still systems vulnerable to 18-year-old Microsoft Excel vulnerabilities, and, unsurprisingly, cybercriminals are taking advantage of that fact.

The US Cybersecurity and Infrastructure Security Agency (CISA) recently updated its catalog of known exploited vulnerabilities (KEVs), a list of flaws that have been confirmed to have been exploited in the wild, to add CVE-2009-0238, a bug in Microsoft Excel first discovered in 2009.



Leave a Comment

Your email address will not be published. Required fields are marked *