CVE-2016-7262
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Microsoft Office Security Feature Bypass Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted cell that is mishandled upon a click, aka "Microsoft Office Security Feature Bypass Vulnerability."
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 58% (אחוזון 100) נכון ל-24/7/2026
מוצרים מושפעים
microsoft: excel; microsoft: excel viewer; microsoft: office compatibility pack
קישורים
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-… PatchVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-… PatchVendor Advisory
- http://www.securityfocus.com/bid/94660 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037441 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/94660 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037441 Broken LinkThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource