First published: Wed Sep 14 2016(Updated: )
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3381.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Excel | =2007-sp3 | |
Microsoft Office Excel | =2010-sp2 | |
Microsoft Office Excel | =2013-sp1 | |
Microsoft Office Excel | =2013-sp1 | |
Microsoft Office Excel | =2016 | |
Microsoft Office Excel Viewer | ||
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3363 has been rated as critical due to its ability to allow remote code execution.
To fix CVE-2016-3363, users should apply the Microsoft security updates released for affected versions.
CVE-2016-3363 affects Microsoft Excel 2007 SP3, 2010 SP2, 2013 SP1, 2016, Office Compatibility Pack SP3, and Excel Viewer.
CVE-2016-3363 is classified as a memory corruption vulnerability that can be exploited through crafted documents.
Exploiting CVE-2016-3363 allows an attacker to execute arbitrary code on the affected system.