CVE-2016-7263
published 2016-12-20CVE-2016-7263: Microsoft Excel for Mac 2011 and Excel 2016 for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a…
PriorityP346high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
19.15%
97.0th percentile
Microsoft Excel for Mac 2011 and Excel 2016 for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel_for_mac | — | — |
| microsoft | excel_for_mac | — | — |
| msrc | microsoft_excel_2016_for_mac | — | — |
| msrc | microsoft_excel_for_mac_2011 | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Office Memory Corruption Vulnerability
vendor_msrc·2016-12-13·CVSS 7.8
CVE-2016-7263 [HIGH] Microsoft Office Memory Corruption Vulnerability
Microsoft Office Memory Corruption Vulnerability
Description: A remote code execution vulnerability exists in Microsoft Office software when the Office software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Exploitation of the vulnerability requires that a user open a specially crafted fil
GHSA
GHSA-pj8h-q9j3-qpvv: Microsoft Excel for Mac 2011 and Excel 2016 for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption)
ghsa_unreviewed·2022-05-14
CVE-2016-7263 [HIGH] CWE-119 GHSA-pj8h-q9j3-qpvv: Microsoft Excel for Mac 2011 and Excel 2016 for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption)
Microsoft Excel for Mac 2011 and Excel 2016 for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
No detection rules found.
No public exploits indexed.
Unit42
Palo Alto Networks Unit 42 Vulnerability Research December 2016 Disclosures
blogs_unit42·2016-12-16·CVSS 7.8
[HIGH] Palo Alto Networks Unit 42 Vulnerability Research December 2016 Disclosures
Threat Research Center
Threat Research
Vulnerabilities
## Palo Alto Networks Unit 42 Vulnerability Research December 2016 Disclosures
Unit 42
Published: December 16, 2016
Threat Research
Vulnerabilities
Adobe Flash
ICloud
ITunes
Microsoft Office
Safari
As part of Unit 42’s ongoing threat research, we can now disclose that Palo Alto Networks Unit 42 researchers have reported six vulnerabilities that have been fixed by Apple, Adobe and Microsoft.
This includes two vulnerabilities in Apple WebKit and impacts iCloud for Windows , Safari , iTunes for Windows , tvOS and iOS .
CVE-2016-7639: Tongbo Luo
CVE-2016-7642: Tongbo Luo
This includes three code execution vulnerabilities affecting Adobe Flash (APSB16-39) .
CVE-2016-7873: Tao Yan
CVE-2016-7874: Tao Yan
CVE-2016-7871: T
Unit42
Palo Alto Networks Unit 42 Vulnerability Research December 2016 Disclosures
blogs_unit42·2016-12-16·CVSS 7.8
CVE-2016-7639 [HIGH] Palo Alto Networks Unit 42 Vulnerability Research December 2016 Disclosures
As part of Unit 42’s ongoing threat research, we can now disclose that Palo Alto Networks Unit 42 researchers have reported six vulnerabilities that have been fixed by Apple, Adobe and Microsoft.
This includes two vulnerabilities in Apple WebKit and impacts iCloud for Windows, Safari, iTunes for Windows, tvOS and iOS.
1. CVE-2016-7639: Tongbo Luo
2. CVE-2016-7642: Tongbo Luo
This includes three code execution vulnerabilities affecting Adobe Flash (APSB16-39).
1. CVE-2016-7873: Tao Yan
2. CVE-2016-7874: Tao Yan
3. CVE-2016-7871: Tao Yan
And this includes one memory corruption vulnerability affecting Microsoft Office for the Mac (MS16-148):
1. CVE-2016-7263: Jin Chen
For current customers with a Threat Prevention subscription, Palo Alto Networks has also released IPS signatures provid
Talos
Microsoft Patch Tuesday - December 2016
blogs_talos·2016-12-13·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - December 2016
The final patch Tuesday of 2016 has arrived. Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month's release contains 12 bulletins addressing 48 vulnerabilities. Six bulletins are rated critical and address vulnerabilities in Internet Explorer, Edge, Microsoft Graphics Components, Microsoft Uniscribe, and Adobe Flash Player. The remaining seven bulletins are rated important and address vulnerabilities in various Windows components including kernel, crypto driver, and installer.
### Bulletins Rated Critical Microsoft bulletins MS16-144 through MS16-148 and MS16-154 are rated as critical in this month's release.
MS16-144 is the Internet Explorer bulletin for this month. It addresses a total of ni
Talos
Microsoft Patch Tuesday - December 2016
blogs_talos·2016-12-13·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - December 2016
## Microsoft Patch Tuesday - December 2016
The final patch Tuesday of 2016 has arrived. Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month's release contains 12 bulletins addressing 48 vulnerabilities. Six bulletins are rated critical and address vulnerabilities in Internet Explorer, Edge, Microsoft Graphics Components, Microsoft Uniscribe, and Adobe Flash Player. The remaining seven bulletins are rated important and address vulnerabilities in various Windows components including kernel, crypto driver, and installer.
## Bulletins Rated Critical Microsoft bulletins MS16-144 through MS16-148 and MS16-154 are rated as critical in this month's release.
MS16-144 is the Internet Explorer bulletin
Bugzilla
CVE-2016-8685 CVE-2016-8686 CVE-2016-8694 CVE-2016-8695 CVE-2016-8696 CVE-2016-8697 CVE-2016-8698 CVE-2016-8699 CVE-2016-8700 CVE-2016-8701 CVE-2016-8702 CVE-2016-8703 CVE-2017-7263 potrace: Multiple
bugzilla·2016-10-17·CVSS 5.5
CVE-2016-8685 [MEDIUM] CVE-2016-8685 CVE-2016-8686 CVE-2016-8694 CVE-2016-8695 CVE-2016-8696 CVE-2016-8697 CVE-2016-8698 CVE-2016-8699 CVE-2016-8700 CVE-2016-8701 CVE-2016-8702 CVE-2016-8703 CVE-2017-7263 potrace: Multiple
CVE-2016-8685 CVE-2016-8686 CVE-2016-8694 CVE-2016-8695 CVE-2016-8696 CVE-2016-8697 CVE-2016-8698 CVE-2016-8699 CVE-2016-8700 CVE-2016-8701 CVE-2016-8702 CVE-2016-8703 CVE-2017-7263 potrace: Multiple security issues
Multiple issues in potrace were assigned CVEs on oss-security.
References:
http://seclists.org/oss-sec/2016/q4/153
https://blogs.gentoo.org/ago/2016/08/08/potrace-multiple-three-null-pointer-dereference-in-bm_readbody_bmp-bitmap_io-c/
AddressSanitizer: SEGV on unknown address 0x4f027b in bm_readbody_bmp /var/tmp/portage/media-gfx/potrace-1.12/work/potrace-1.12/src/bitmap_io.c:717:4
Use CVE-2016-8694.
AddressSanitizer: SEGV on unknown address 0x4f0957 in bm_readbody_bmp /var/tmp/portage/media-gfx/potrace-1.12/work/potrace-1.12/src/bitmap_io.c:744:4
Use CVE-2016-8695.
http://www.securityfocus.com/bid/94668http://www.securitytracker.com/id/1037441https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-148http://www.securityfocus.com/bid/94668http://www.securitytracker.com/id/1037441https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-148
2016-12-20
Published