CVE-2016-7262

Confirmed PUBLISHED

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow...

Vendor: Microsoft Product: Excel
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
7.8 High EPSS 58.2%

At a Glance

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted cell that is mishandled upon a click, aka "Microsoft Office Security Feature Bypass Vulnerability."

cisa
CVE Published
Dec 20, 2016
Exploitation Reported
Mar 03, 2022
CVSS
7.8 High
EPSS
58.2%
Low complexity Unauthenticated

CVE References

  • MS16-148 docs.microsoft.com · Vendor Advisory https://docs.microsoft.com/en-us/security-updates/securitybulletins/2...
  • 94660 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/94660
  • 1037441 securitytracker.com · VDB Entry http://www.securitytracker.com/id/1037441