PT-2016-1240 · Microsoft · Word 2016+11
Publicado
2016-02-09
·
Atualizado
2018-10-12
·
CVE-2016-0022
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Office software versions prior to the fixed version
Microsoft Word versions prior to the fixed version
Microsoft Word 2007 SP3
Office 2010 SP2
Word 2010 SP2
Word 2013 SP1
Word 2013 RT SP1
Word 2016
Word for Mac 2011
Word 2016 for Mac
Office Compatibility Pack SP3
Word Viewer
Word Automation Services on SharePoint Server 2013 SP1
Office Web Apps Server 2013 SP1
SharePoint Server 2013 SP1
Description
The issue is caused by a buffer overflow in Microsoft Office software, including Microsoft Word and Office Web Apps Server, allowing remote attackers to execute arbitrary code via a crafted Office document. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system, install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations
For Microsoft Office software, update to the latest version to resolve the issue.
For Microsoft Word 2007 SP3, apply the available patch.
For Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps Server 2013 SP1, and SharePoint Server 2013 SP1, apply the available patches or updates.
As a temporary workaround, consider restricting access to crafted Office documents until a patch is available.
Avoid opening suspicious or untrusted Office documents until the issue is resolved.
Correção
RCE
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Office
Office Word
Office 2010
Office Compatibility Pack
Office Web Apps Server
Sharepoint Server
Word 2010
Word 2013
Word 2016
Word Automation Services
Word Viewer
Word For Mac