First published: Wed Sep 14 2016(Updated: )
Microsoft Excel 2007 SP3, Excel 2010 SP2, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Excel for Mac | =2007-sp3 | |
Microsoft Excel for Mac | =2010-sp2 | |
Microsoft Excel Viewer | ||
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3359 has a critical severity rating, indicating that it can allow remote code execution.
To fix CVE-2016-3359, apply the latest security updates provided by Microsoft for the affected versions of Excel and Office.
CVE-2016-3359 affects Microsoft Excel 2007 SP3, Excel 2010 SP2, the Office Compatibility Pack SP3, and Excel Viewer.
CVE-2016-3359 is classified as a memory corruption vulnerability that can result in arbitrary code execution.
Yes, CVE-2016-3359 can be exploited by sending crafted documents via email, which can lead to remote code execution on the user’s system.