SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2016-7262

Microsoft Office Security Feature Bypass Vulnerability

KEVHIGH 7.8EPSS 57.9%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 March 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted cell that is mishandled upon a click, aka "Microsoft Office Security Feature Bypass Vulnerability."

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
57.86% probability · 99th percentile
CISA KEV
Listed 3 March 2022 · due 24 March 2022
Affected
microsoft/excel · microsoft/excel viewer · microsoft/office compatibility pack
Source
secure@microsoft.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2016-7262

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.