Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

17-year-old Office RCE back on KEV

3 min read
16:08UTC

CVE-2009-0238 was cut during the Bush administration. Attackers dug it back up and CISA put it on the active-exploitation list in April.

TechnologyAssessed
Key takeaway

Attackers are reviving ancient CVEs that still work against unpatched legacy estates, particularly in the public sector.

The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2009-0238, a seventeen-year-old Microsoft Office remote-code-execution vulnerability, to its Known Exploited Vulnerabilities (KEV) catalogue on 14 April 2026 after confirming active exploitation in the wild 1. The bug was first patched in 2009 during the second Bush administration, before iPhones ran iOS 3. Attackers are mining old CVE databases for flaws that still work against legacy Office deployments, particularly in public-sector estates where migration lag is measured in decades rather than years.

The attack vector is macro-based. A Microsoft Office macro is a scripting command stored inside a document file; a malicious macro embedded in an Office document, delivered over email, runs attacker code on the target machine when opened. In modern Office installations the exploit is blocked by later patches and default macro restrictions. In unpatched legacy installations, still widespread in NHS trusts, council back-office systems and small public-sector departments, the chain completes often enough that the ransomware affiliates buying access have revived it.

For a Chief Information Officer in local government or a trust finance director, a CVE on the KEV catalogue is no longer a line item in the backlog. It is a federal compliance deadline in the United States and, through the Information Commissioner's Office (ICO)'s recent practice of treating NCSC guidance as enforceable data-protection baseline, a UK enforcement posture too. The public-sector legacy-Office problem has moved from technical debt to regulatory exposure.

Deep Analysis

In plain English

CVE-2009-0238 is a security flaw that was discovered in Microsoft Office back in 2009, during the George W. Bush presidency. Microsoft released a fix at the time, but many organisations never applied it. In April 2026, CISA, the US government's cybersecurity agency, confirmed that attackers are actively exploiting this 17-year-old vulnerability to break into computers, particularly in hospitals and government offices that still run old versions of Office. The attack works by sending a specially crafted Excel file. When someone opens it, the file runs hidden code that gives the attacker access to the computer. For organisations that have never updated Office, this vulnerability is still just as dangerous today as it was in 2009.

Deep Analysis
Root Causes

Healthcare and public sector organisations in the UK and US have disproportionate legacy Office estate because their procurement cycles are tied to five-to-ten-year software licensing agreements that were signed before Microsoft's 2022 macro policy change. Many NHS trusts and US county government agencies still run Office 2010 or 2013 on clinical workstations because the cost of upgrade, data migration, and clinical-software compatibility testing is not within annual IT budgets.

Legacy Office estate also persists because of embedded macros in operational workflows: financial reconciliation spreadsheets, clinical data import tools, and court document management systems were built on Excel macros in the 2010s and have never been refactored. Patching the underlying Office vulnerability would require refactoring those workflows as well as applying the update.

What could happen next?
  • Consequence

    KEV compliance deadlines for CVE-2009-0238 will force board-level decisions at NHS trusts and US county government agencies about legacy Office replacement, converting what was a technical-debt backlog item into a regulatory compliance deadline.

  • Risk

    The attack chain targeting this CVE is being actively developed and traded; threat actors who acquire it gain a reliable initial access mechanism against the high-value, low-patch healthcare and government sectors.

First Reported In

Update #1 · Stryker MDM wipe exposes identity perimeter

ENISA· 17 Apr 2026
Read original
Causes and effects
This Event
17-year-old Office RCE back on KEV
The legacy Office estate in healthcare and the public sector is now a regulatory deadline, not a technical-debt ticket.
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.