CVE-2009-3129 is a memory corruption vulnerability in Microsoft Excel and related products, including Office for Mac and Excel Viewer. It allows remote attackers to execute arbitrary code by crafting a malicious spreadsheet with an invalid FEATHEADER record. This vulnerability has a CVSS score of 7.8 (High) due to its potential for complete compromise of confidentiality, integrity, and availability, requiring user interaction (opening a malicious file) but with low attack complexity. It is actively exploited in the wild, with publicly available Metasploit modules and multiple mentions in community discussions and media coverage, including its use in sophisticated campaigns like "Red October."
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2002CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2002:sp3:*:*:*:*:*:* | ||
2003CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2003:sp3:*:*:*:*:*:* | ||
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2007:sp1:*:*:*:*:*:* | ||
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2007:sp2:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:excel_viewer:-:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.