CVE-2016-0140

Description

Microsoft Office 2007 SP3, Office 2010 SP2, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka Microsoft Office Memory Corruption Vulnerability.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
36.012

Associated Vulnerability

VulnerabilityOS Platform
Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Office 2013 (KB3115016) 64-Bit EditionWindows
Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Office 2013 (KB3115016) 32-Bit EditionWindows
Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Office 2016 (KB3115103) 64-Bit EditionWindows
Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Office 2016 (KB3115103) 32-Bit EditionWindows
Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Office 2007 suites (KB2984943)Windows
Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Office 2007 suites (KB2984938)Windows
Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Office 2010 (KB3101520) 64-Bit EditionWindows
Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Office 2010 (KB3101520) 32-Bit EditionWindows
Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Office 2010 (KB3054984) 64-Bit EditionWindows
Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Office 2010 (KB3054984) 32-Bit EditionWindows
Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Office Compatibility Pack Service Pack 3 (KB3115115)Windows
Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Office 2010 (KB3115121) 64-Bit EditionWindows
Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Office 2010 (KB3115121) 32-Bit EditionWindows
Microsoft Office Graphics Remote Code Execution Vulnerability for Word Viewer (KB3115132)Windows
Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Word 2016 (KB3115094) 64-Bit EditionWindows
Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Word 2016 (KB3115094) 32-Bit EditionWindows
Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Office Word 2007 (KB3115116)Windows
Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Word 2013 (KB3115025) 64-Bit EditionWindows
Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Word 2013 (KB3115025) 32-Bit EditionWindows
Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Word 2010 (KB3115123) 64-Bit EditionWindows
Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Word 2010 (KB3115123) 32-Bit EditionWindows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-20528Security Update for Microsoft Office 2013 (KB3115016) 64-Bit Edition
PATCH-20527Security Update for Microsoft Office 2013 (KB3115016) 32-Bit Edition
PATCH-20532Security Update for Microsoft Office 2016 (KB3115103) 64-Bit Edition
PATCH-20531Security Update for Microsoft Office 2016 (KB3115103) 32-Bit Edition
PATCH-20517Security Update for Microsoft Office 2007 suites (KB2984943)
PATCH-20516Security Update for Microsoft Office 2007 suites (KB2984938)
PATCH-20521Security Update for Microsoft Office 2010 (KB3054984) 32-Bit Edition
PATCH-20520Security Update for Microsoft Office 2010 (KB3115121) 64-Bit Edition
PATCH-20519Security Update for Microsoft Office 2010 (KB3115121) 32-Bit Edition
PATCH-20536Security Update for Word Viewer (KB3115132)
PATCH-20534Security Update for Microsoft Word 2016 (KB3115094) 64-Bit Edition
PATCH-20533Security Update for Microsoft Word 2016 (KB3115094) 32-Bit Edition
PATCH-20518Security Update for Microsoft Office Word 2007 (KB3115116)
PATCH-20530Security Update for Microsoft Word 2013 (KB3115025) 64-Bit Edition
PATCH-20529Security Update for Microsoft Word 2013 (KB3115025) 32-Bit Edition
PATCH-20525Security Update for Microsoft Word 2010 (KB3115123) 32-Bit Edition

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234