Executive brief
Microsoft Office contains a use-after-free vulnerability (CWE-416) when handling objects in memory. This flaw allows a remote attacker to execute arbitrary code on a target system if a user opens a specially crafted file.
Affected products
- Microsoft Office 2010 SP2
- Microsoft Office 2013 SP1
- Microsoft Office 2016
Timeline
- 2017-05-12: disclosed: NVD Published Date
- 2017-05-12: advisory: MSRC advisory published
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog