First published: Tue Dec 20 2016(Updated: )
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, and Excel Services on SharePoint Server 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office Information Disclosure Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Excel | =2007-sp3 | |
Microsoft Office Excel | =2010-sp2 | |
Microsoft Office Excel | =2013-sp1 | |
Microsoft Office Excel | =2013-sp1 | |
Microsoft Office Excel | =2016 | |
Microsoft Office Excel Viewer | ||
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 | |
Microsoft SharePoint Server 2010 | =2007-sp3 | |
Microsoft SharePoint Server 2010 | =2010-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7265 is rated as important, indicating a significant risk of exploitation.
To mitigate CVE-2016-7265, you should apply the relevant security updates provided by Microsoft for the affected versions of Excel and SharePoint.
CVE-2016-7265 affects Microsoft Excel 2007 SP3, 2010 SP2, 2013 SP1, 2016, and Excel Services on SharePoint Server 2007 and 2010.
Yes, CVE-2016-7265 can allow remote attackers to obtain sensitive information from the memory of affected processes.
There are no known workarounds for CVE-2016-7265; the best approach is to apply the security updates provided by Microsoft.