Executive brief
A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory. An attacker can exploit this by convincing a user to open a specially crafted file, allowing the execution of arbitrary code in the context of the current user.
Affected products
- Microsoft Office 2010
- Microsoft Word 2007, 2010, 2013, 2016
- Microsoft SharePoint Server 2010, 2013, 2016
- Microsoft Office Web Apps Server 2010, 2013
- Microsoft Office Online Server 2016
- Microsoft Word Viewer
- Microsoft Word Automation Services
Timeline
- 2017-10-17: disclosed: Initial disclosure and vendor advisory published.
- 2017-11-01: other: Third-party analysis of zero-day exploit published.
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.