vendor:
Excel 2016
by:
John Page (aka hyp3rlinx)
7.5
CVSS
HIGH
Error Import Based XML External Entity Injection
611
CWE
Product Name: Excel 2016
Affected Version From: 2016 v1901
Affected Version To: 2016 v1901
Patch Exists: No
Related CWE: N/A
CPE: a:microsoft:excel:2016
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2019
Microsoft Excel 2016 1901 – XML External Entity Injection
Excel query from file feature is vulnerable to "Error" based XML External Entity attacks, if the user chooses the "Import as Html page" functionality upon receiving errors importing a specially crafted XML file. This can result in potential remote data exfiltration, user interaction is required to exploit this vulnerability. Tested successfuly Windows 10 .NET framework version v4.0.30319.
Mitigation:
Microsoft has not released a patch for this vulnerability. Users should avoid opening untrusted files in Excel.