First published: Tue Apr 12 2016(Updated: )
Microsoft Excel 2007 SP3, Excel 2010 SP2, Office Compatibility Pack SP3, Excel Services on SharePoint Server 2007 SP3, and Excel Services on SharePoint Server 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Excel for Mac | =2007-sp3 | |
Microsoft Excel for Mac | =2010-sp2 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 | |
Microsoft SharePoint Designer | =2007-sp3 | |
Microsoft SharePoint Foundation | =2010-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0136 has a critical severity rating, allowing remote attackers to execute arbitrary code.
To fix CVE-2016-0136, install the latest security updates provided by Microsoft for the affected versions of Excel and SharePoint.
CVE-2016-0136 affects Microsoft Excel 2007 SP3 and Excel 2010 SP2.
CVE-2016-0136 allows attackers to execute arbitrary code via maliciously crafted Office documents.
Yes, both SharePoint Server 2007 SP3 and SharePoint Server 2010 SP2 are vulnerable to CVE-2016-0136.