CVE-2016-3279 is a remote code execution vulnerability affecting multiple versions of Microsoft Office, including Excel, PowerPoint, and Word 2010, 2013, and 2016, as well as Office Web Apps 2010 and SharePoint Server 2010. An attacker can exploit this by tricking a user into opening a specially crafted XLA file. The vulnerability has a CVSSv3 score of 5.5 (MEDIUM), indicating a local attack vector with low complexity, requiring user interaction, and potentially leading to high integrity impact. While the FAUCET Risk Score is high at 90/100 and it has received some community discussion and media coverage, there is no evidence of active exploitation, nor are there public exploits available in Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2010:sp2:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2013:sp1:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:excel_rt:2013:sp1:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.