CVE-2016-7262
high-risk
Published 2016-12-20
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted cell that is mishandled upon a click, aka "Microsoft Office Security Feature Bypass Vulnerability."
Do I need to act?
!
87.1% chance of exploitation in next 30 days
EPSS score — higher than 13% of all CVEs
!
CISA KEV: actively exploited in the wild
On the Known Exploited Vulnerabilities catalog — federal agencies must patch
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.8/10
High
LOCAL
/ LOW complexity
Affected Products (7)
Affected Vendors
References (7)
Broken Link
http://www.securityfocus.com/bid/94660
Broken Link
http://www.securitytracker.com/id/1037441
Broken Link
http://www.securityfocus.com/bid/94660
Broken Link
http://www.securitytracker.com/id/1037441
65
/ 100
high-risk
Severity
24/34 · High
Exploitability
27/34 · High
Exposure
14/34 · Moderate