CVE-2016-3279
MEDIUMMicrosoft Office and Excel - Remote Code Execution via Crafted XLA File
Title source: llmDescription
Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Excel 2016, Word 2016, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to execute arbitrary code via a crafted XLA file, aka "Microsoft Office Remote Code Execution Vulnerability."
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1036274
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1036275
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-088
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/91587
Scores
CVSS v3
5.5
EPSS
0.1642
EPSS Percentile
96.7%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Details
CWE
CWE-254
Status
published
Products (14)
microsoft/excel
2010 sp2
microsoft/excel
2013 sp1
microsoft/excel
2016
microsoft/excel_rt
2013 sp1
microsoft/office
2010 sp2
microsoft/office_web_apps
2010 sp2
microsoft/powerpoint
2010 sp2
microsoft/powerpoint
2013 sp1
microsoft/powerpoint_rt
2013 sp1
microsoft/sharepoint_server
2010 sp2
... and 4 more
Published
Jul 13, 2016
Tracked Since
Feb 18, 2026