Microsoft Office 2016 Click-to-Run (C2R) allows a remote code execution vulnerability due to the way files are handled in memory, aka "Microsoft Excel Remote Code Execution Vulnerability".
Exploit prediction scoring system (EPSS) score
EPSS Score 0.324
EPSS Ranking 96.7%