Executive brief
A security feature bypass vulnerability in Microsoft Excel occurs when the application improperly handles input in crafted cells. An attacker can achieve arbitrary command execution if a user clicks on a specially crafted cell within a malicious file.
Affected products
- Microsoft Excel 2007 SP3
- Microsoft Excel 2010 SP2
- Microsoft Excel 2013 SP1
- Microsoft Excel 2013 RT SP1
- Microsoft Excel 2016
- Microsoft Office Compatibility Pack SP3
- Microsoft Excel Viewer
Timeline
- 2016-12-13: disclosed: Initial release of MS16-148 security bulletin.
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.