Executive brief
A remote code execution vulnerability exists in Microsoft Office 2010, 2013, and 2016 when the software fails to properly handle objects in memory. An attacker could exploit this by convincing a user to open a specially crafted file, leading to full system compromise.
Affected products
- Microsoft Office 2010 SP2
- Microsoft Office 2013 SP1
- Microsoft Office 2016 -
Timeline
- 2017-05-12: disclosed: NVD Published Date
- 2022-02-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog