CVE-2016-7262
highCVSS v3 Base Score
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
87.1%
Exploitation probability in 30 days
Top 1% most likely to be exploited
Attack Characteristics
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Confidentiality
High
Integrity
High
Availability
High
Published: December 20, 2016 (3433 days ago)
Last Modified: April 22, 2026
Vendor: Microsoft
Source: NVD
⚠️ CISA Known Exploited Vulnerability
Added to KEV: 2022-03-03
Remediation Due: 2022-03-24 (⚠ 1513d overdue)
Vulnerability Report
Generated by CyberWatcher
Description
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted cell that is mishandled upon a click, aka "Microsoft Office Security Feature Bypass Vulnerability."
CWE
NVD-CWE-noinfoAffected Products
microsoft excelmicrosoft excel viewermicrosoft office compatibility pack