Junglewise Threat Intelligence

CVE-2016-7262: Microsoft Office Security Feature Bypass Vulnerability

CVE-2016-7262 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-03-03

Technologies: Microsoft Excel 2016, Microsoft Excel. Vendors: Microsoft.

Executive brief

A security feature bypass vulnerability in Microsoft Excel occurs when the application improperly handles input in crafted cells. An attacker can achieve arbitrary command execution if a user clicks on a specially crafted cell within a malicious file.

Affected products

  • Microsoft Excel 2007 SP3
  • Microsoft Excel 2010 SP2
  • Microsoft Excel 2013 SP1
  • Microsoft Excel 2013 RT SP1
  • Microsoft Excel 2016
  • Microsoft Office Compatibility Pack SP3
  • Microsoft Excel Viewer

Timeline

  • 2016-12-13: disclosed: Initial release of MS16-148 security bulletin.
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats