CVE-2008-0081 is an unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Excel Viewer 2003, and Office 2004 for Mac, allowing remote attackers to execute arbitrary code through crafted macros. This critical vulnerability has a CVSS score of 9.8, indicating a network-based attack with low complexity and high impact on confidentiality, integrity, and availability. While not listed in CISA KEV, exploit code is publicly available via ExploitDB, and it garners significant community discussion, suggesting potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2000CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2000:sp3:*:*:*:*:*:* | ||
2002CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2002:sp3:*:*:*:*:*:* | ||
2003CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2003:sp2:*:*:*:*:*:* | ||
2003CPE matchmatch criteria | cpe:2.3:a:microsoft:excel_viewer:2003:*:*:*:*:*:*:* | ||
2004CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2004:*:*:*:*:macos:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.