cbcvebase.
CVE-2016-7264
published 2016-12-20

CVE-2016-7264: Microsoft Excel 2007 SP3, Office Compatibility Pack SP3, Excel Viewer, Excel for Mac 2011, and Excel 2016 for Mac allow remote attackers to obtain sensitive…

PriorityP338high7.1CVSS 3.0
AVLACLPRNUIRSUCHINAH
EPSS
23.21%
97.5th percentile
Microsoft Excel 2007 SP3, Office Compatibility Pack SP3, Excel Viewer, Excel for Mac 2011, and Excel 2016 for Mac allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office Information Disclosure Vulnerability."

Affected

8 ranges
VendorProductVersion rangeFixed in
microsoftexcel
microsoftexcel_for_mac
microsoftexcel_for_mac
msrcmicrosoft_excel_2007_service_pack_3
msrcmicrosoft_excel_2016_for_mac
msrcmicrosoft_excel_for_mac_2011
msrcmicrosoft_excel_viewer_2007_service_pack_3
msrcmicrosoft_office_compatibility_pack_service_pack_3

CVSS provenance

nvdv3.07.1HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
vendor_msrc7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.