CVE-2016-7262

microsoft excel, microsoft excel viewer, microsoft office compatibility pack

Published 20 Dec 2016 · updated 17 Jun 2026 · Analyzed

7.8 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 3 Mar 2022, with a remediation deadline of 24 Mar 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted cell that is mishandled upon a click, aka "Microsoft Office Security Feature Bypass Vulnerability."

References