CVE-2016-0057
Description
Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016 does not properly sign an unspecified binary file, which allows local users to gain privileges via a Trojan horse file with a crafted signature, aka Microsoft Office Security Feature Bypass Vulnerability.
Risk Information
Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.702
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Security Update for Microsoft Office 2007 suites (KB2956110) | Windows |
| Security Update for Microsoft Office InfoPath 2007 (KB3114426) | Windows |
| Security Update for Microsoft Office Word 2007 (KB3114901) | Windows |
| Security Update for Microsoft Office 2010 (KB2956063) 32-Bit Edition | Windows |
| Security Update for Microsoft Office 2010 (KB3114873) 32-Bit Edition | Windows |
| Security Update for Microsoft Office 2010 (KB3114873) 64-Bit Edition | Windows |
| Security Update for Microsoft InfoPath 2010 (KB3114414) 32-Bit Edition | Windows |
| Security Update for Microsoft InfoPath 2010 (KB3114414) 64-Bit Edition | Windows |
| Security Update for Microsoft Word 2010 (KB3114878) 32-Bit Edition | Windows |
| Security Update for Microsoft Word 2010 (KB3114878) 64-Bit Edition | Windows |
| Security Update for Microsoft Office 2013 (KB3039746) 32-Bit Edition | Windows |
| Security Update for Microsoft InfoPath 2013 (KB3114833) 32-Bit Edition | Windows |
| Security Update for Microsoft InfoPath 2013 (KB3114833) 64-Bit Edition | Windows |
| Security Update for Microsoft Word 2013 (KB3114824) 32-Bit Edition | Windows |
| Security Update for Microsoft Word 2013 (KB3114824) 64-Bit Edition | Windows |
| Security Update for Microsoft Office 2016 (KB3114690) 32-Bit Edition | Windows |
| Security Update for Microsoft Word 2016 (KB3114855) 32-Bit Edition | Windows |
| Security Update for Microsoft Word 2016 (KB3114855) 64-Bit Edition | Windows |
| Security Update for Word Viewer (KB3114812) | Windows |
| Security Update for Microsoft Office Compatibility Pack Service Pack 3 (KB3114900) | Windows |
| Security Update for Microsoft Office Outlook 2007 (KB2880510) | Windows |
| Security Update for Microsoft Outlook 2013 (KB3114829) 32-Bit Edition | Windows |
| Security Update for Microsoft Outlook 2013 (KB3114829) 64-Bit Edition | Windows |
| Security Update for Microsoft Outlook 2016 (KB3114861) 32-Bit Edition | Windows |
| Security Update for Microsoft Outlook 2016 (KB3114861) 64-Bit Edition | Windows |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-20199 | Security Update for Microsoft Office 2007 suites (KB2956110) |
| PATCH-20200 | Security Update for Microsoft Office InfoPath 2007 (KB3114426) |
| PATCH-20201 | Security Update for Microsoft Office Word 2007 (KB3114901) |
| PATCH-20202 | Security Update for Microsoft Office 2010 (KB2956063) 32-Bit Edition |
| PATCH-20203 | Security Update for Microsoft Office 2010 (KB3114873) 32-Bit Edition |
| PATCH-20204 | Security Update for Microsoft Office 2010 (KB3114873) 64-Bit Edition |
| PATCH-20205 | Security Update for Microsoft InfoPath 2010 (KB3114414) 32-Bit Edition |
| PATCH-20206 | Security Update for Microsoft InfoPath 2010 (KB3114414) 64-Bit Edition |
| PATCH-20207 | Security Update for Microsoft Word 2010 (KB3114878) 32-Bit Edition |
| PATCH-20209 | Security Update for Microsoft Office 2013 (KB3039746) 32-Bit Edition |
| PATCH-20210 | Security Update for Microsoft InfoPath 2013 (KB3114833) 32-Bit Edition |
| PATCH-20211 | Security Update for Microsoft InfoPath 2013 (KB3114833) 64-Bit Edition |
| PATCH-20212 | Security Update for Microsoft Word 2013 (KB3114824) 32-Bit Edition |
| PATCH-20213 | Security Update for Microsoft Word 2013 (KB3114824) 64-Bit Edition |
| PATCH-20214 | Security Update for Microsoft Office 2016 (KB3114690) 32-Bit Edition |
| PATCH-20215 | Security Update for Microsoft Word 2016 (KB3114855) 32-Bit Edition |
| PATCH-20216 | Security Update for Microsoft Word 2016 (KB3114855) 64-Bit Edition |
| PATCH-20217 | Security Update for Word Viewer (KB3114812) |
| PATCH-20219 | Security Update for Microsoft Office Outlook 2007 (KB2880510) |
| PATCH-20330 | Security Update for Microsoft Outlook 2013 (KB3114829) 32-Bit Edition |
| PATCH-20331 | Security Update for Microsoft Outlook 2013 (KB3114829) 64-Bit Edition |
| PATCH-20332 | Security Update for Microsoft Outlook 2016 (KB3114861) 32-Bit Edition |
| PATCH-20333 | Security Update for Microsoft Outlook 2016 (KB3114861) 64-Bit Edition |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234