CVE-2016-7262
published 2016-12-20CVE-2016-7262: Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted…
PriorityP180high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
58.20%
99.0th percentile
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted cell that is mishandled upon a click, aka "Microsoft Office Security Feature Bypass Vulnerability."
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| msrc | microsoft_excel_2007_service_pack_3 | — | — |
| msrc | microsoft_excel_2010_service_pack_2 | — | — |
| msrc | microsoft_excel_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_excel_2013_service_pack_1 | — | — |
| msrc | microsoft_excel_2016 | — | — |
| msrc | microsoft_excel_viewer_2007_service_pack_3 | — | — |
| msrc | microsoft_office_compatibility_pack_service_pack_3 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger condition: vulnerability is exploited when a user clicks on a specific crafted cell in a malicious Excel document — monitor for unexpected process spawning from Excel upon cell interaction ↗
- →Affected products to target for detection: Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer — flag unpatched versions in asset inventory ↗
- →Attack vector is file-sharing / phishing delivery of a specially crafted Office document — monitor email and file-share ingestion points for suspicious Excel files triggering child process creation from EXCEL.EXE ↗
- ·The update KB3128023 only applies to specific configurations of Microsoft Office 2010; not all Office 2010 installs will be offered the patch — verify applicability per configuration before assuming coverage ↗
- ·Updates may apply to shared Office components across multiple products/versions not explicitly listed in the Affected Software table — scope patching broadly across all Office 2007/2010 products sharing the vulnerable component ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Microsoft Office Security Feature Bypass Vulnerability
cisa·2022-03-03·CVSS 7.8
CVE-2016-7262 [HIGH] CWE-20 Microsoft Office Security Feature Bypass Vulnerability
Vulnerability: Microsoft Office Security Feature Bypass Vulnerability
Affected: Microsoft Excel
A security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who successfully exploited the vulnerability could execute arbitrary commands.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-7262
Remediation Due Date: 2022-03-24
Microsoft
Microsoft Excel Security Feature Bypass Vulnerability
vendor_msrc·2016-12-13·CVSS 7.8
CVE-2016-7262 [HIGH] Microsoft Excel Security Feature Bypass Vulnerability
Microsoft Excel Security Feature Bypass Vulnerability
Description: A security feature bypass vulnerability exists when Microsoft Excel improperly handles input. An attacker who successfully exploited the vulnerability could execute arbitrary commands.
In a file-sharing attack scenario, an attacker could provide a specially crafted document file designed to exploit the vulnerability, and then convince users to open the document file and interact with the document by clicking on a specific cell.
The update addresses the vulnerability by correcting how Microsoft Excel handles input.
FAQ: I have Microsoft Word 2010 installed. Why am I not being offered the 3128023 update?
The 3128023 update only applies to systems running specific configurations of Microsoft Office 2010. Some configurations
GHSA
GHSA-r3jw-q3j2-jqv3: Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-as
ghsa_unreviewed·2022-05-14
CVE-2016-7262 [HIGH] CWE-20 GHSA-r3jw-q3j2-jqv3: Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-as
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted cell that is mishandled upon a click, aka "Microsoft Office Security Feature Bypass Vulnerability."
VulnCheck
Microsoft Office Security Feature Bypass Vulnerability
vulncheck·2016·CVSS 7.8
CVE-2016-7262 [HIGH] CWE-20 Microsoft Office Security Feature Bypass Vulnerability
Microsoft Office Security Feature Bypass Vulnerability
A security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who successfully exploited the vulnerability could execute arbitrary commands.
Affected: Microsoft Excel
Required Action: Apply updates per vendor instructions.
Exploitation References: https://go.recordedfuture.com/hubfs/reports/cta-2020-0603.pdf; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-03-24
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - December 2016
blogs_talos·2016-12-13·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - December 2016
The final patch Tuesday of 2016 has arrived. Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month's release contains 12 bulletins addressing 48 vulnerabilities. Six bulletins are rated critical and address vulnerabilities in Internet Explorer, Edge, Microsoft Graphics Components, Microsoft Uniscribe, and Adobe Flash Player. The remaining seven bulletins are rated important and address vulnerabilities in various Windows components including kernel, crypto driver, and installer.
### Bulletins Rated Critical Microsoft bulletins MS16-144 through MS16-148 and MS16-154 are rated as critical in this month's release.
MS16-144 is the Internet Explorer bulletin for this month. It addresses a total of ni
Talos
Microsoft Patch Tuesday - December 2016
blogs_talos·2016-12-13·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - December 2016
## Microsoft Patch Tuesday - December 2016
The final patch Tuesday of 2016 has arrived. Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month's release contains 12 bulletins addressing 48 vulnerabilities. Six bulletins are rated critical and address vulnerabilities in Internet Explorer, Edge, Microsoft Graphics Components, Microsoft Uniscribe, and Adobe Flash Player. The remaining seven bulletins are rated important and address vulnerabilities in various Windows components including kernel, crypto driver, and installer.
## Bulletins Rated Critical Microsoft bulletins MS16-144 through MS16-148 and MS16-154 are rated as critical in this month's release.
MS16-144 is the Internet Explorer bulletin
http://www.securityfocus.com/bid/94660http://www.securitytracker.com/id/1037441https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-148http://www.securityfocus.com/bid/94660http://www.securitytracker.com/id/1037441https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-148https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-7262
2016-12-20
Published
2022-03-03
Added to CISA KEV
Exploited in the wild