PT-2016-1403 · Microsoft · Office

Published

2016-03-08

·

Updated

2018-10-12

·

CVE-2016-0057

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Office versions 2007 SP3 through 2016
Description The issue is related to errors in the binary file signing process in Microsoft Office. It allows a local attacker to elevate privileges using a specially crafted file. This can be achieved by creating a Trojan horse file with a crafted signature. The vulnerability exploits an invalidly signed binary, enabling an attacker to host malicious code in a similarly configured binary. To exploit this, the attacker needs write access to the target location containing the invalidly signed binary.
Recommendations For Microsoft Office versions 2007 SP3 through 2016, consider restricting write access to sensitive locations to minimize the risk of exploitation. As a temporary workaround, avoid using unsigned or potentially malicious binaries until a patch is available. Restrict access to areas where binary files are executed to prevent potential elevation of privileges. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00702
CVE-2016-0057

Affected Products

Office