Executive brief
Microsoft Word contains a memory corruption vulnerability when processing crafted RTF data. Successful exploitation allows remote attackers to execute arbitrary code or cause a denial of service.
Affected products
- Microsoft Word 2003 SP3
- Microsoft Word 2007 SP3
- Microsoft Word 2010 SP1, SP2
- Microsoft Word 2013 All versions, including RT
- Microsoft Word Viewer
- Microsoft Office Compatibility Pack SP3
- Microsoft Office for Mac 2011
- Microsoft Word Automation Services on SharePoint Server 2010 SP1/SP2, 2013
- Microsoft Office Web Apps 2010 SP1/SP2, 2013
Timeline
- 2014-03: exploited: Exploited in the wild in March 2014.
- 2022-02-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.