CVE-2016-7262
microsoft excel, microsoft excel viewer, microsoft office compatibility pack
Published 20 Dec 2016 · updated 17 Jun 2026 · Analyzed
7.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Mar 2022, with a remediation deadline of 24 Mar 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted cell that is mishandled upon a click, aka "Microsoft Office Security Feature Bypass Vulnerability."
References
- www.securityfocus.com/bid/94660 · Broken Link, Third Party Advisory, VDB Entry
- www.securitytracker.com/id/1037441 · Broken Link, Third Party Advisory, VDB Entry
- docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-148 · Patch, Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-7262 · US Government Resource