Executive brief
A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory. An attacker could exploit this by convincing a user to open a specially crafted file, potentially leading to full system compromise.
Affected products
- Microsoft Office 2007 Service Pack 3
- Microsoft Office 2010 Service Pack 2
- Microsoft Office 2013 Service Pack 1
- Microsoft Office 2013 RT Service Pack 1
- Microsoft Office 2016 All versions
Timeline
- 2017-07-11: disclosed: Initial publication of vulnerability details and patches.
- 2022-02-25: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.