CVE-2016-7267Improper Input Validation in Microsoft Excel

Severity
5.5MEDIUMNVD
EPSS
21.7%
top 4.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 20
Latest updateMay 14

Description

Microsoft Excel 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 misparses file formats, which makes it easier for remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Security Feature Bypass Vulnerability."

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages1 packages

NVDmicrosoft/excel2010, 2013, 2016+2

🔴Vulnerability Details

2
GHSA
GHSA-8pxc-7h2p-mh7g: Microsoft Excel 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 misparses file formats, which makes it easier for remote attackers to execute arbitrary code2022-05-14
CVEList
CVE-2016-7267: Microsoft Excel 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 misparses file formats, which makes it easier for remote attackers to execute arbitrary code2016-12-20

📋Vendor Advisories

1
Microsoft
Microsoft Excel Security Feature Bypass Vulnerability2016-12-13
CVE-2016-7267 — Improper Input Validation in Microsoft | cvebase