Vulnerability record · CVE-2016-7262 · published 20 December 2016
CVE-2016-7262: Microsoft Excel security feature bypass enables command execution
Microsoft · Excel
A crafted cell in affected Microsoft Excel and Excel Viewer versions is mishandled when a user clicks it, allowing a security feature bypass that leads to arbitrary command execution. The flaw affects Excel 2007 through 2016, the Office Compatibility Pack, and Excel Viewer, and it is listed in CISA's Known Exploited Vulnerabilities catalog, so it warrants prompt remediation.
Description
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted cell that is mishandled upon a click, aka "Microsoft Office Security Feature Bypass Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows arbitrary command execution, is listed in CISA KEV as exploited in the wild, and has a very high EPSS score, though it requires user interaction to trigger.
What it is
A crafted cell in affected Microsoft Excel and Excel Viewer versions is mishandled when a user clicks it, allowing a security feature bypass that leads to arbitrary command execution. The flaw affects Excel 2007 through 2016, the Office Compatibility Pack, and Excel Viewer, and it is listed in CISA's Known Exploited Vulnerabilities catalog, so it warrants prompt remediation.
Impact
An attacker who gets a victim to open and click a malicious cell can execute arbitrary commands in the context of the logged-on user, giving full compromise of confidentiality, integrity, and availability on that host.
Attack surface
Reached locally through a crafted Excel document or cell that the victim must open and click, so exploitation requires user interaction and no prior authentication. The CVSS vector confirms local access, no privileges required, and user interaction required.
Exploitation
CVE-2016-7262 is listed in CISA KEV with a 2022-03-03 addition date, indicating known exploitation in the wild, and EPSS shows a 30-day probability of 0.579 at the 99th percentile. No ransomware campaign use is documented in the record.
What to do
- Apply the Microsoft MS16-148 updates for all affected Excel, Excel Viewer, and Office Compatibility Pack installations.
- Remove or block Excel Viewer and the Office Compatibility Pack where they are not required.
- Enforce Mark-of-the-Web and Protected View so documents from untrusted sources cannot execute content on click.
- Restrict users from opening email and web-sourced Office files without prior inspection.
- Track KEV due dates and verify remediation across all endpoints running affected Office versions.
Detection
- Monitor for Excel or Excel Viewer spawning child processes such as cmd.exe, powershell.exe, or wscript.exe.
- Alert on Office applications loading documents from email attachments, downloads, or temporary internet directories.
- Review endpoint telemetry for anomalous process creation shortly after a user opens an Excel file.
- Search for known malicious Office document hashes and cell-based exploit indicators in email and file gateways.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2016-7262 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Microsoft Office Security Feature Bypass Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/94660 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1037441 | Broken LinkThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-148 | PatchVendor Advisory |
| http://www.securityfocus.com/bid/94660 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1037441 | Broken LinkThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-148 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-7262 | US Government Resource |
Track CVE-2016-7262 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-7262), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.