CVE-2016-0122
published 2016-04-12CVE-2016-0122: Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Word 2016 for Mac, Office Compatibility Pack SP3, and Excel Viewer…
PriorityP260high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
41.13%
98.5th percentile
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Word 2016 for Mac, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | word_for_mac | — | — |
| msrc | microsoft_excel_2007_service_pack_3 | — | — |
| msrc | microsoft_excel_2010_service_pack_2 | — | — |
| msrc | microsoft_excel_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_excel_2013_service_pack_1 | — | — |
| msrc | microsoft_excel_2016 | — | — |
| msrc | microsoft_excel_viewer | — | — |
| msrc | microsoft_office_compatibility_pack_service_pack_3 | — | — |
| msrc | microsoft_word_2016_for_mac | — | — |
Detection & IOCsextracted from sources · hover to see the quote
urlhttps://smsecurity.net/wp-content/uploads/2016/04/Microsoft_Office_Excel_Out-of-Bounds_Read_RCE.xlsm↗
- →Trigger vector is a specially crafted .xlsm file (macro-enabled Excel workbook) delivered via email attachment or web download; monitor for Excel opening .xlsm files from untrusted sources. ↗
- →In email-based attacks, the crafted Office file is sent directly to the user; alert on inbound emails with .xlsm attachments targeting unpatched Excel 2007/2010/2013/2016 installations. ↗
- →In web-based attacks, the payload is hosted on a website; monitor web proxy logs for downloads of .xlsm files from newly registered or compromised domains. ↗
- →Exploitation results in arbitrary code running as the current user; monitor for child processes spawned by Excel (e.g., cmd.exe, powershell.exe, wscript.exe) as a post-exploitation indicator. ↗
- ·The vulnerability is an out-of-bounds read triggered by a memory corruption condition when Excel fails to properly handle objects in memory; the exploit file type is specifically .xlsm (macro-enabled workbook), not generic .xlsx. ↗
- ·Microsoft assessed exploitation as 'More Likely' for both latest and older software releases at time of disclosure; the exploit was publicly disclosed via Exploit-DB (EDB-39694) with a working PoC .xlsm file. ↗
- ·The shared vulnerable component means the patch (MS16-042) may apply to Office products beyond those explicitly listed as affected, including Visio, Compatibility Pack, and Excel Viewer. ↗
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Office Remote Code Execution Vulnerability
vendor_msrc·2016-04-12·CVSS 7.8
CVE-2016-0122 [HIGH] Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Exploitation of the vulnerability requires that a user open a specially crafted file w
GHSA
GHSA-94rx-pxvr-752c: Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Word 2016 for Mac, Office Compatibility Pack SP3, and Excel V
ghsa_unreviewed·2022-05-14
CVE-2016-0122 [HIGH] CWE-119 GHSA-94rx-pxvr-752c: Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Word 2016 for Mac, Office Compatibility Pack SP3, and Excel V
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Word 2016 for Mac, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
No detection rules found.
http://www.securitytracker.com/id/1035525https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-042https://www.exploit-db.com/exploits/39694/http://www.securitytracker.com/id/1035525https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-042https://www.exploit-db.com/exploits/39694/
2016-04-12
Published