CVE-2018-0907: Microsoft Excel

High severity, CVSS 7.8. EPSS: 5.9% chance of exploitation in the next 30 days.

Microsoft Excel 2007 SP3, Microsoft Excel 2010 SP2, Microsoft Excel 2013 SP1, Microsoft Excel 2016, Microsoft Office 2016 Click-to-Run and Microsoft Office 2016 for Mac allow a security feature bypass vulnerability due to how macro settings are enforced, aka "Microsoft Office Excel Security Feature Bypass".

Affected products

  • Microsoft Excel: version 2007 only; version 2013 only; version 2016 only
  • Microsoft Office: version 2016 only

Published 2018-03-14. Last modified 2026-06-17.