Executive brief
A memory corruption vulnerability in Microsoft Office and Word allows remote attackers to execute arbitrary code via a specially crafted RTF document. The flaw stems from improper restriction of operations within the bounds of a memory buffer.
Affected products
- Microsoft Word 2007 SP2
- Microsoft Office 2010 SP2
- Microsoft Word 2013 SP1
- Microsoft Word 2013 RT SP1
- Microsoft Word 2016
- Microsoft Word for Mac 2011
- Microsoft Word 2016 for Mac
- Microsoft Office Compatibility Pack SP3
- Microsoft Word Viewer
- Microsoft Word Automation Services on SharePoint Server 2010 SP2
- Microsoft Word Automation Services on SharePoint Server 2013 SP1
- Microsoft Office Web Apps 2010 SP2
- Microsoft Office Web Apps Server 2013 SP1
- Microsoft Office Online Server
Timeline
- 2016-10-11: patched: Microsoft released security bulletin MS16-121 to address the vulnerability.
- 2022-03-03: kev added: CISA added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog.
- 2022-03-03: disclosed