cbcvebase.
CVE-2016-0122
published 2016-04-12

CVE-2016-0122: Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Word 2016 for Mac, Office Compatibility Pack SP3, and Excel Viewer…

PriorityP260high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
41.13%
98.5th percentile
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Word 2016 for Mac, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

Affected

13 ranges
VendorProductVersion rangeFixed in
microsoftexcel
microsoftexcel
microsoftexcel
microsoftexcel
microsoftword_for_mac
msrcmicrosoft_excel_2007_service_pack_3
msrcmicrosoft_excel_2010_service_pack_2
msrcmicrosoft_excel_2013_rt_service_pack_1
msrcmicrosoft_excel_2013_service_pack_1
msrcmicrosoft_excel_2016
msrcmicrosoft_excel_viewer
msrcmicrosoft_office_compatibility_pack_service_pack_3
msrcmicrosoft_word_2016_for_mac

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://smsecurity.net/wp-content/uploads/2016/04/Microsoft_Office_Excel_Out-of-Bounds_Read_RCE.xlsm
urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/39694.zip
filenameMicrosoft_Office_Excel_Out-of-Bounds_Read_RCE.xlsm
  • Trigger vector is a specially crafted .xlsm file (macro-enabled Excel workbook) delivered via email attachment or web download; monitor for Excel opening .xlsm files from untrusted sources.
  • In email-based attacks, the crafted Office file is sent directly to the user; alert on inbound emails with .xlsm attachments targeting unpatched Excel 2007/2010/2013/2016 installations.
  • In web-based attacks, the payload is hosted on a website; monitor web proxy logs for downloads of .xlsm files from newly registered or compromised domains.
  • Exploitation results in arbitrary code running as the current user; monitor for child processes spawned by Excel (e.g., cmd.exe, powershell.exe, wscript.exe) as a post-exploitation indicator.
  • ·The vulnerability is an out-of-bounds read triggered by a memory corruption condition when Excel fails to properly handle objects in memory; the exploit file type is specifically .xlsm (macro-enabled workbook), not generic .xlsx.
  • ·Microsoft assessed exploitation as 'More Likely' for both latest and older software releases at time of disclosure; the exploit was publicly disclosed via Exploit-DB (EDB-39694) with a working PoC .xlsm file.
  • ·The shared vulnerable component means the patch (MS16-042) may apply to Office products beyond those explicitly listed as affected, including Visio, Compatibility Pack, and Excel Viewer.

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.