VulnerabilityAnalyzed
CVE-2016-7262
Microsoft Office Security Feature Bypass Vulnerability
KEVHIGH 7.8EPSS 57.9%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 March 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted cell that is mishandled upon a click, aka "Microsoft Office Security Feature Bypass Vulnerability."
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 57.86% probability · 99th percentile
- CISA KEV
- Listed 3 March 2022 · due 24 March 2022
- Affected
- microsoft/excel · microsoft/excel viewer · microsoft/office compatibility pack
- Source
- secure@microsoft.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2016-7262
References
- http://www.securityfocus.com/bid/94660Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037441Broken Link, Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-148Patch, Vendor Advisory
- http://www.securityfocus.com/bid/94660Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037441Broken Link, Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-148Patch, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-7262US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.