CVE-2016-3279
Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Excel 2016, Word 2016, Word Automation Services on SharePoint…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.4%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Excel 2016, Word 2016, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to execute arbitrary code via a crafted XLA file, aka "Microsoft Office Remote Code Execution Vulnerability."
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 16.42% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-254
- Affected
- microsoft/excel · microsoft/excel rt · microsoft/office · microsoft/office web apps · microsoft/powerpoint · microsoft/powerpoint rt · microsoft/sharepoint server · microsoft/word · microsoft/word rt
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/91587
- http://www.securitytracker.com/id/1036274
- http://www.securitytracker.com/id/1036275
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-088
- http://www.securityfocus.com/bid/91587
- http://www.securitytracker.com/id/1036274
- http://www.securitytracker.com/id/1036275
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-088
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.