PT-2016-1240 · Microsoft · Word 2016+11

Publicado

2016-02-09

·

Atualizado

2018-10-12

·

CVE-2016-0022

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Office software versions prior to the fixed version Microsoft Word versions prior to the fixed version Microsoft Word 2007 SP3 Office 2010 SP2 Word 2010 SP2 Word 2013 SP1 Word 2013 RT SP1 Word 2016 Word for Mac 2011 Word 2016 for Mac Office Compatibility Pack SP3 Word Viewer Word Automation Services on SharePoint Server 2013 SP1 Office Web Apps Server 2013 SP1 SharePoint Server 2013 SP1
Description The issue is caused by a buffer overflow in Microsoft Office software, including Microsoft Word and Office Web Apps Server, allowing remote attackers to execute arbitrary code via a crafted Office document. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system, install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations For Microsoft Office software, update to the latest version to resolve the issue. For Microsoft Word 2007 SP3, apply the available patch. For Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps Server 2013 SP1, and SharePoint Server 2013 SP1, apply the available patches or updates. As a temporary workaround, consider restricting access to crafted Office documents until a patch is available. Avoid opening suspicious or untrusted Office documents until the issue is resolved.

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00501
CVE-2016-0022

Produtos afetados

Office
Office Word
Office 2010
Office Compatibility Pack
Office Web Apps Server
Sharepoint Server
Word 2010
Word 2013
Word 2016
Word Automation Services
Word Viewer
Word For Mac