Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

17-year-old Office RCE back on KEV

3 min read
12:09UTC

CVE-2009-0238 was cut during the Bush administration. Attackers dug it back up and CISA put it on the active-exploitation list in April.

TechnologyAssessed
Key takeaway

Attackers are reviving ancient CVEs that still work against unpatched legacy estates, particularly in the public sector.

The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2009-0238, a seventeen-year-old Microsoft Office remote-code-execution vulnerability, to its Known Exploited Vulnerabilities (KEV) catalogue on 14 April 2026 after confirming active exploitation in the wild 1. The bug was first patched in 2009 during the second Bush administration, before iPhones ran iOS 3. Attackers are mining old CVE databases for flaws that still work against legacy Office deployments, particularly in public-sector estates where migration lag is measured in decades rather than years.

The attack vector is macro-based. A Microsoft Office macro is a scripting command stored inside a document file; a malicious macro embedded in an Office document, delivered over email, runs attacker code on the target machine when opened. In modern Office installations the exploit is blocked by later patches and default macro restrictions. In unpatched legacy installations, still widespread in NHS trusts, council back-office systems and small public-sector departments, the chain completes often enough that the ransomware affiliates buying access have revived it.

For a Chief Information Officer in local government or a trust finance director, a CVE on the KEV catalogue is no longer a line item in the backlog. It is a federal compliance deadline in the United States and, through the Information Commissioner's Office (ICO)'s recent practice of treating NCSC guidance as enforceable data-protection baseline, a UK enforcement posture too. The public-sector legacy-Office problem has moved from technical debt to regulatory exposure.

Deep Analysis

In plain English

CVE-2009-0238 is a security flaw that was discovered in Microsoft Office back in 2009, during the George W. Bush presidency. Microsoft released a fix at the time, but many organisations never applied it. In April 2026, CISA, the US government's cybersecurity agency, confirmed that attackers are actively exploiting this 17-year-old vulnerability to break into computers, particularly in hospitals and government offices that still run old versions of Office. The attack works by sending a specially crafted Excel file. When someone opens it, the file runs hidden code that gives the attacker access to the computer. For organisations that have never updated Office, this vulnerability is still just as dangerous today as it was in 2009.

Deep Analysis
Root Causes

Healthcare and public sector organisations in the UK and US have disproportionate legacy Office estate because their procurement cycles are tied to five-to-ten-year software licensing agreements that were signed before Microsoft's 2022 macro policy change. Many NHS trusts and US county government agencies still run Office 2010 or 2013 on clinical workstations because the cost of upgrade, data migration, and clinical-software compatibility testing is not within annual IT budgets.

Legacy Office estate also persists because of embedded macros in operational workflows: financial reconciliation spreadsheets, clinical data import tools, and court document management systems were built on Excel macros in the 2010s and have never been refactored. Patching the underlying Office vulnerability would require refactoring those workflows as well as applying the update.

What could happen next?
  • Consequence

    KEV compliance deadlines for CVE-2009-0238 will force board-level decisions at NHS trusts and US county government agencies about legacy Office replacement, converting what was a technical-debt backlog item into a regulatory compliance deadline.

  • Risk

    The attack chain targeting this CVE is being actively developed and traded; threat actors who acquire it gain a reliable initial access mechanism against the high-value, low-patch healthcare and government sectors.

First Reported In

Update #1 · Stryker MDM wipe exposes identity perimeter

ENISA· 17 Apr 2026
Read original
Causes and effects
This Event
17-year-old Office RCE back on KEV
The legacy Office estate in healthcare and the public sector is now a regulatory deadline, not a technical-debt ticket.
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.