CVE-2016-3317

Description

Microsoft Office 2010 SP2, Word 2007 SP3, Word 2010 SP2, Word for Mac 2011, Word 2016 for Mac, and Word Viewer allow remote attackers to execute arbitrary code via a crafted file, aka Microsoft Office Memory Corruption Vulnerability.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
30.017

Associated Vulnerability

VulnerabilityOS Platform
Microsoft OneNote Information Disclosure Vulnerability for Microsoft Office 2013 (KB3115427) 64-Bit EditionWindows
Microsoft OneNote Information Disclosure Vulnerability for Microsoft Office 2013 (KB3115427) 32-Bit EditionWindows
Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Office 2007 suites (KB3114893)Windows
Microsoft OneNote Information Disclosure Vulnerability for Microsoft Office 2016 (KB3115415) 64-Bit EditionWindows
Microsoft OneNote Information Disclosure Vulnerability for Microsoft Office 2016 (KB3115415) 32-Bit EditionWindows
Microsoft OneNote Information Disclosure Vulnerability for Microsoft Office 2010 (KB3114869) 64-Bit EditionWindows
Microsoft OneNote Information Disclosure Vulnerability for Microsoft Office 2010 (KB3114869) 32-Bit EditionWindows
Microsoft Office Graphics Remote Code Execution Vulnerability for Word Viewer (KB3115479)Windows
Microsoft OneNote Information Disclosure Vulnerability for Microsoft OneNote 2016 (KB3115419) 64-Bit EditionWindows
Microsoft OneNote Information Disclosure Vulnerability for Microsoft OneNote 2016 (KB3115419) 32-Bit EditionWindows
Microsoft OneNote Information Disclosure Vulnerability for Microsoft Office OneNote 2007 (KB3114456)Windows
Microsoft OneNote Information Disclosure Vulnerability for Microsoft OneNote 2010 (KB3114885) 64-Bit EditionWindows
Microsoft OneNote Information Disclosure Vulnerability for Microsoft OneNote 2010 (KB3114885) 32-Bit EditionWindows
Microsoft OneNote Information Disclosure Vulnerability for Microsoft Office 2013 (KB3114340) 64-Bit EditionWindows
Microsoft OneNote Information Disclosure Vulnerability for Microsoft Office 2013 (KB3114340) 32-Bit EditionWindows
Microsoft OneNote Information Disclosure Vulnerability for Microsoft Office 2007 suites (KB3114442)Windows
Microsoft OneNote Information Disclosure Vulnerability for Microsoft Office 2010 (KB3114400) 64-Bit EditionWindows
Microsoft OneNote Information Disclosure Vulnerability for Microsoft Office 2010 (KB3114400) 32-Bit EditionWindows
Microsoft Office Graphics Remote Code Execution Vulnerability for Word Viewer (KB3115480)Windows
Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Office Word 2007 (KB3115465)Windows
Microsoft Office Memory Corruption Vulnerability for Microsoft Office 2010 (KB3115468) 32-Bit EditionWindows
Microsoft Office Memory Corruption Vulnerability for Microsoft Office 2010 (KB3115468) 64-Bit EditionWindows
Microsoft Office Memory Corruption Vulnerability for Microsoft Word 2010 (KB3115471) 32-Bit EditionWindows
Microsoft Office Memory Corruption Vulnerability for Microsoft Word 2010 (KB3115471) 64-Bit EditionWindows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-21280Security Update for Microsoft Office 2013 (KB3115427) 64-Bit Edition
PATCH-21279Security Update for Microsoft Office 2013 (KB3115427) 32-Bit Edition
PATCH-21286Security Update for Microsoft Office 2016 (KB3115415) 64-Bit Edition
PATCH-21285Security Update for Microsoft Office 2016 (KB3115415) 32-Bit Edition
PATCH-21291Security Update for Word Viewer (KB3115479)
PATCH-21288Security Update for Microsoft OneNote 2016 (KB3115419) 64-Bit Edition
PATCH-21287Security Update for Microsoft OneNote 2016 (KB3115419) 32-Bit Edition
PATCH-21265Security Update for Microsoft Office OneNote 2007 (KB3114456)
PATCH-21274Security Update for Microsoft OneNote 2010 (KB3114885) 64-Bit Edition
PATCH-21273Security Update for Microsoft OneNote 2010 (KB3114885) 32-Bit Edition
PATCH-21278Security Update for Microsoft Office 2013 (KB3114340) 64-Bit Edition
PATCH-21277Security Update for Microsoft Office 2013 (KB3114340) 32-Bit Edition
PATCH-21263Security Update for Microsoft Office 2007 suites (KB3114442)
PATCH-21268Security Update for Microsoft Office 2010 (KB3114400) 64-Bit Edition
PATCH-21267Security Update for Microsoft Office 2010 (KB3114400) 32-Bit Edition
PATCH-21292Security Update for Word Viewer (KB3115480)
PATCH-21266Security Update for Microsoft Office Word 2007 (KB3115465)
PATCH-21271Security Update for Microsoft Office 2010 (KB3115468) 32-Bit Edition
PATCH-21272Security Update for Microsoft Office 2010 (KB3115468) 64-Bit Edition
PATCH-21275Security Update for Microsoft Word 2010 (KB3115471) 32-Bit Edition

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234