VulnerabilityModified
CVE-2016-7267
Microsoft Excel 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 misparses file formats, which makes it easier for remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Security Feature Bypass Vulnerability."
MEDIUM 5.5EPSS 19.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 19.4%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Excel 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 misparses file formats, which makes it easier for remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Security Feature Bypass Vulnerability."
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 19.41% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- microsoft/excel
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/94664Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037441Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-148
- http://www.securityfocus.com/bid/94664Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037441Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-148
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.