7.1

CVE-2016-7265

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, and Excel Services on SharePoint Server 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office Information Disclosure Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Excel Version 2007 Update sp3
Microsoft ≫ Excel Version 2010 Update sp2
Microsoft ≫ Excel Version 2013 Update sp1
Microsoft ≫ Excel Version 2013 Update sp1 SwEdition rt
Microsoft ≫ Excel Version 2016
Microsoft ≫ Sharepoint Server Version 2007 Update sp3
Microsoft ≫ Sharepoint Server Version 2010 Update sp2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 22.57% 0.974
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 1.8 5.2
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
NIST 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:N/A:P
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

http://www.securitytracker.com/id/1037441
Third Party Advisory
VDB Entry
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-148
http://www.securityfocus.com/bid/94721
Third Party Advisory
VDB Entry