Rule Category

Alert Message

Rule Explanation

Microsoft Excel 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 misparses file formats, which makes it easier for remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Security Feature Bypass Vulnerability." Impact: CVSS base score 5.5 CVSS impact score 3.6 CVSS exploitability score 1.8 confidentialityImpact NONE integrityImpact HIGH availabilityImpact HIGH Details: Ease of Attack:

What To Look For

Known Usage

No public information

False Positives

No known false positives

Contributors

MITRE ATT&CK Framework

Tactic:

Technique:

For reference, see the MITRE ATT&CK vulnerability types here: https://attack.mitre.org

CVE

Additional Links

CVE Additional Information

CVE-2016-7267
Microsoft Excel 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 misparses file formats, which makes it easier for remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Security Feature Bypass Vulnerability."
Details
Severity Base Score5.5
Impact Score3.6 Exploit Score1.8
Confidentiality ImpactNONE Integrity ImpactHIGH
Availability ImpactNONE Access Vector
Authentication Ease of Access