CVE-2016-7267

MEDIUM

Microsoft Excel - Improper Input Validation

Title source: rule

Description

Microsoft Excel 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 misparses file formats, which makes it easier for remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Security Feature Bypass Vulnerability."

Scores

CVSS v3 5.5
EPSS 0.2171
EPSS Percentile 95.7%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Classification

CWE
CWE-20
Status published

Affected Products (5)

microsoft/excel
microsoft/excel
microsoft/excel
microsoft/excel
n/a/n/a

Timeline

Published Dec 20, 2016
Tracked Since Feb 18, 2026