← Vulnerability feed

Vulnerability record · CVE-2016-7262 · published 20 December 2016

CVE-2016-7262: Microsoft Excel security feature bypass enables command execution

Microsoft · Excel

A crafted cell in affected Microsoft Excel and Excel Viewer versions is mishandled when a user clicks it, allowing a security feature bypass that leads to arbitrary command execution. The flaw affects Excel 2007 through 2016, the Office Compatibility Pack, and Excel Viewer, and it is listed in CISA's Known Exploited Vulnerabilities catalog, so it warrants prompt remediation.

7.8 CVSS 3.1 High CISA KEV since 3 Mar 2022 EPSS 58% · top 0.9%
7.8CVSS 3.1 base score, v2 6.8
58%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted cell that is mishandled upon a click, aka "Microsoft Office Security Feature Bypass Vulnerability."

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw allows arbitrary command execution, is listed in CISA KEV as exploited in the wild, and has a very high EPSS score, though it requires user interaction to trigger.

What it is

A crafted cell in affected Microsoft Excel and Excel Viewer versions is mishandled when a user clicks it, allowing a security feature bypass that leads to arbitrary command execution. The flaw affects Excel 2007 through 2016, the Office Compatibility Pack, and Excel Viewer, and it is listed in CISA's Known Exploited Vulnerabilities catalog, so it warrants prompt remediation.

Impact

An attacker who gets a victim to open and click a malicious cell can execute arbitrary commands in the context of the logged-on user, giving full compromise of confidentiality, integrity, and availability on that host.

Attack surface

Reached locally through a crafted Excel document or cell that the victim must open and click, so exploitation requires user interaction and no prior authentication. The CVSS vector confirms local access, no privileges required, and user interaction required.

Exploitation

CVE-2016-7262 is listed in CISA KEV with a 2022-03-03 addition date, indicating known exploitation in the wild, and EPSS shows a 30-day probability of 0.579 at the 99th percentile. No ransomware campaign use is documented in the record.

What to do

  • Apply the Microsoft MS16-148 updates for all affected Excel, Excel Viewer, and Office Compatibility Pack installations.
  • Remove or block Excel Viewer and the Office Compatibility Pack where they are not required.
  • Enforce Mark-of-the-Web and Protected View so documents from untrusted sources cannot execute content on click.
  • Restrict users from opening email and web-sourced Office files without prior inspection.
  • Track KEV due dates and verify remediation across all endpoints running affected Office versions.

Detection

  • Monitor for Excel or Excel Viewer spawning child processes such as cmd.exe, powershell.exe, or wscript.exe.
  • Alert on Office applications loading documents from email attachments, downloads, or temporary internet directories.
  • Review endpoint telemetry for anomalous process creation shortly after a user opens an Excel file.
  • Search for known malicious Office document hashes and cell-based exploit indicators in email and file gateways.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2016-7262 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Microsoft Office Security Feature Bypass Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-7262 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-1297Microsoft Excel memory handling flaw allows remote code executionCVE-2019-1297 is a remote code execution vulnerability in Microsoft Excel caused by improper handling of objects in memory. An attacker who convinces…KEVEPSS 22%analysed8.8CVE-2019-0541Microsoft MSHTML engine input validation flaw allows remote code executionThe MSHTML engine in Microsoft Office, Internet Explorer and related viewers fails to properly validate input, allowing remote code execution. Becaus…KEVEPSS 53%analysed8.8CVE-2018-0798Microsoft Office Equation Editor memory corruption RCEEquation Editor in Microsoft Office 2007 through 2016 mishandles objects in memory, producing an out-of-bounds write (CWE-787) that can be turned int…KEVEPSS 95%analysed8.8CVE-2015-2424Microsoft Office memory corruption via crafted documentCVE-2015-2424 is an out-of-bounds write (CWE-787) in Microsoft PowerPoint and Word that is triggered when a crafted Office document is opened. A remo…KEVEPSS 40%analysed8.8CVE-2009-0238Microsoft Excel invalid object access allows remote code executionMicrosoft Excel and related viewers (Excel 2000 through 2007, Excel Viewer, Office Compatibility Pack, and Office for Mac 2004/2008) fail to handle a…KEVEPSS 43%analysed8.8CVE-2007-0671Microsoft Excel remote code execution via malformed fileCVE-2007-0671 is an unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, that allows re…KEVEPSS 43%analysed7.8CVE-2021-42292Microsoft Excel security feature bypass via crafted fileCVE-2021-42292 is a security feature bypass in Microsoft Excel and related Office products. The record gives only a one-line description, so the exac…KEVEPSS 43%analysed7.8CVE-2018-0802Microsoft Office Equation Editor Memory Corruption RCEEquation Editor in Microsoft Office 2007, 2010, 2013, and 2016 mishandles objects in memory, causing an out-of-bounds write (CWE-787) that can lead t…KEVEPSS 93%analysed

Source: NIST National Vulnerability Database (record CVE-2016-7262), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.