First published: Tue Dec 20 2016(Updated: )
Microsoft Excel 2007 SP3, Office Compatibility Pack SP3, Excel Viewer, Excel for Mac 2011, and Excel 2016 for Mac allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office Information Disclosure Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Excel for Mac | =2007-sp3 | |
Microsoft Excel | =2011 | |
Microsoft Excel | =2016 | |
Microsoft Excel Viewer | ||
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7264 has a severity rating of medium due to the potential for sensitive information disclosure and denial of service.
To fix CVE-2016-7264, apply the latest security updates provided by Microsoft for the affected versions of Excel.
CVE-2016-7264 affects Microsoft Excel 2007 SP3, Excel Viewer, Office Compatibility Pack SP3, and Excel for Mac 2011 and 2016.
The impact of CVE-2016-7264 includes potential unauthorized access to sensitive information and a denial of service through out-of-bounds read.
Yes, CVE-2016-7264 can be exploited remotely through specially crafted documents that target the affected Excel applications.