PT-2016-2485 · Microsoft · Excel 2013 Rt+15
Published
2016-07-12
·
Updated
2018-10-12
·
CVE-2016-3279
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Office 2010 SP2
Excel 2010 SP2
PowerPoint 2010 SP2
Word 2010 SP2
Excel 2013 SP1
PowerPoint 2013 SP1
Word 2013 SP1
Excel 2013 RT SP1
PowerPoint 2013 RT SP1
Word 2013 RT SP1
Excel 2016
Word 2016
Word Automation Services on SharePoint Server 2010 SP2
Office Web Apps 2010 SP2
Description
The issue is caused by a buffer overflow and improper handling of file formats, allowing remote attackers to execute arbitrary code via a crafted XLA file. To exploit the vulnerability, an attacker would need to convince a user to open a specially crafted file with an affected version of Microsoft Office software. The security feature bypass by itself does not allow arbitrary code execution, but it can be used in conjunction with another vulnerability to run arbitrary code.
Recommendations
For Microsoft Office 2010 SP2, update to a newer version to mitigate the risk.
For Excel 2010 SP2, avoid using the vulnerable XLA file handling functionality until a patch is available.
For PowerPoint 2010 SP2, restrict access to specially crafted files until the issue is resolved.
For Word 2010 SP2, consider disabling the vulnerable file parsing functionality as a temporary workaround.
For Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, and Word 2013 RT SP1, update to a newer version to mitigate the risk.
For Excel 2016 and Word 2016, avoid using the vulnerable XLA file handling functionality until a patch is available.
For Word Automation Services on SharePoint Server 2010 SP2 and Office Web Apps 2010 SP2, restrict access to specially crafted files until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Excel 2010
Excel 2013
Excel 2013 Rt
Excel 2016
Office 2010
Office Excel
Office Powerpoint
Office Web Apps 2010
Office Word
Powerpoint 2010
Powerpoint 2013 Rt
Sharepoint Server 2010
Word 2010
Word 2013
Word 2013 Rt
Word 2016