An old Microsoft Excel security flaw could let hackers hijack your entire system, so fix now


  • CISA adds an 18-year-old Excel bug (CVE-2009-0238) to the KEV catalog
  • Vulnerability enables RCE via malicious Excel files, patched long ago
  • Outdated systems still at risk; agencies ordered to patch by April 28

As incredible as it sounds, there are still systems out there that are vulnerable to 18-year-old Microsoft Excel vulnerabilities, and it’s no surprise that cybercriminals are taking advantage of that fact.

The US Cybersecurity and Infrastructure Security Agency (CISA) recently updated its catalog of known exploited vulnerabilities (KEV) – a list of flaws confirmed to be exploited in the wild – to add CVE-2009-0238, a bug in Microsoft Excel first discovered in 2009.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top