cbcvebase.
CVE-2016-7262
published 2016-12-20

CVE-2016-7262: Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted…

PriorityP180high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
58.20%
99.0th percentile
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted cell that is mishandled upon a click, aka "Microsoft Office Security Feature Bypass Vulnerability."

Affected

11 ranges
VendorProductVersion rangeFixed in
microsoftexcel
microsoftexcel
microsoftexcel
microsoftexcel
msrcmicrosoft_excel_2007_service_pack_3
msrcmicrosoft_excel_2010_service_pack_2
msrcmicrosoft_excel_2013_rt_service_pack_1
msrcmicrosoft_excel_2013_service_pack_1
msrcmicrosoft_excel_2016
msrcmicrosoft_excel_viewer_2007_service_pack_3
msrcmicrosoft_office_compatibility_pack_service_pack_3

Detection & IOCsextracted from sources · hover to see the quote

  • Trigger condition: vulnerability is exploited when a user clicks on a specific crafted cell in a malicious Excel document — monitor for unexpected process spawning from Excel upon cell interaction
  • Affected products to target for detection: Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer — flag unpatched versions in asset inventory
  • Attack vector is file-sharing / phishing delivery of a specially crafted Office document — monitor email and file-share ingestion points for suspicious Excel files triggering child process creation from EXCEL.EXE
  • ·The update KB3128023 only applies to specific configurations of Microsoft Office 2010; not all Office 2010 installs will be offered the patch — verify applicability per configuration before assuming coverage
  • ·Updates may apply to shared Office components across multiple products/versions not explicitly listed in the Affected Software table — scope patching broadly across all Office 2007/2010 products sharing the vulnerable component

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.