First published: Thu Nov 10 2016(Updated: )
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Excel | =2007-sp3 | |
Microsoft Office Excel | =2010-sp2 | |
Microsoft Office Excel | =2013-sp1 | |
Microsoft Office Excel | =2013-sp1 | |
Microsoft Office Excel | =2016 | |
Microsoft Excel | =2011 | |
Microsoft Excel | =2016 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7228 is classified with a critical severity rating as it allows remote code execution.
To fix CVE-2016-7228, apply the latest security updates provided by Microsoft for affected Excel versions.
CVE-2016-7228 affects Microsoft Excel 2007 SP3, 2010 SP2, 2013 SP1, 2016, and several versions of Excel for Mac.
Yes, CVE-2016-7228 can be exploited through email attachments containing specially crafted Office documents.
CVE-2016-7228 can lead to unauthorized remote code execution, potentially allowing attackers to take control of affected systems.