CVE-2016-7233

Description

Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2013 SP1, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted Office document, aka Microsoft Office Information Disclosure Vulnerability.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
14.568

Associated Vulnerability

VulnerabilityOS Platform
Microsoft Office Information Disclosure Vulnerability for Microsoft Office Compatibility Pack Service Pack 3 (KB3127889)Windows
Microsoft Office Information Disclosure Vulnerability for Microsoft Excel 2010 (KB3118390) 64-Bit EditionWindows
Microsoft Office Information Disclosure Vulnerability for Microsoft Excel 2010 (KB3118390) 32-Bit EditionWindows
Microsoft Office Information Disclosure Vulnerability for Microsoft Excel 2016 (KB3127904) 64-Bit EditionWindows
Microsoft Office Information Disclosure Vulnerability for Microsoft Excel 2016 (KB3127904) 32-Bit EditionWindows
Microsoft Office Information Disclosure Vulnerability for Microsoft Excel 2013 (KB3127921) 64-Bit EditionWindows
Microsoft Office Information Disclosure Vulnerability for Microsoft Excel 2013 (KB3127921) 32-Bit EditionWindows
Microsoft Office Information Disclosure Vulnerability for Microsoft Office Excel 2007 (KB3118395)Windows
Microsoft Office Information Disclosure Vulnerability for Microsoft Office Excel Viewer 2007 (KB3127893)Windows
Microsoft Office Information Disclosure Vulnerability for Microsoft Office 2010 (KB3127951) 64-Bit EditionWindows
Microsoft Office Information Disclosure Vulnerability for Microsoft Office 2010 (KB3127951) 32-Bit EditionWindows
Microsoft Office Information Disclosure Vulnerability for Microsoft Office Word 2007 (KB3127949)Windows
Microsoft Office Information Disclosure Vulnerability for Microsoft Word 2013 (KB3127932) 64-Bit EditionWindows
Microsoft Office Information Disclosure Vulnerability for Microsoft Word 2013 (KB3127932) 32-Bit EditionWindows
Microsoft Office Information Disclosure Vulnerability for Microsoft Word 2010 (KB3127953) 64-Bit EditionWindows
Microsoft Office Information Disclosure Vulnerability for Microsoft Word 2010 (KB3127953) 32-Bit EditionWindows
Microsoft Office Information Disclosure Vulnerability for Microsoft Office Compatibility Pack Service Pack 3 (KB3127948)Windows
Microsoft Office Information Disclosure Vulnerability for Word Viewer (KB3127962)Windows
Microsoft Office Information Disclosure Vulnerability for Microsoft Office 2007 suites (KB3118396)Windows
Microsoft Office Information Disclosure Vulnerability for Microsoft Office 2007 suites (KB2986253)Windows
Microsoft Office Information Disclosure Vulnerability for Microsoft Office 2010 (KB3115120) 64-Bit EditionWindows
Microsoft Office Information Disclosure Vulnerability for Microsoft Office 2010 (KB3115120) 32-Bit EditionWindows
Microsoft Office Information Disclosure Vulnerability for Microsoft Office 2013 (KB3115153) 64-Bit EditionWindows
Microsoft Office Information Disclosure Vulnerability for Microsoft Office 2013 (KB3115153) 32-Bit EditionWindows
Microsoft Office Information Disclosure Vulnerability for Microsoft Office 2016 (KB3115135) 64-Bit EditionWindows
Microsoft Office Information Disclosure Vulnerability for Microsoft Office 2016 (KB3115135) 32-Bit EditionWindows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-21731Security Update for Microsoft Office Compatibility Pack Service Pack 3 (KB3127889)
PATCH-21722Security Update for Microsoft Excel 2010 (KB3118390) 64-Bit Edition
PATCH-21721Security Update for Microsoft Excel 2010 (KB3118390) 32-Bit Edition
PATCH-21730Security Update for Microsoft Excel 2016 (KB3127904) 64-Bit Edition
PATCH-21729Security Update for Microsoft Excel 2016 (KB3127904) 32-Bit Edition
PATCH-21728Security Update for Microsoft Excel 2013 (KB3127921) 64-Bit Edition
PATCH-21727Security Update for Microsoft Excel 2013 (KB3127921) 32-Bit Edition
PATCH-21717Security Update for Microsoft Office Excel 2007 (KB3118395)
PATCH-21733Security Update for Microsoft Office Excel Viewer 2007 (KB3127893)
PATCH-21720Security Update for Microsoft Office 2010 (KB3127951) 64-Bit Edition
PATCH-21719Security Update for Microsoft Office 2010 (KB3127951) 32-Bit Edition
PATCH-21718Security Update for Microsoft Office Word 2007 (KB3127949)
PATCH-21749Security Update for Microsoft Word 2013 (KB3127932) 64-Bit Edition
PATCH-21748Security Update for Microsoft Word 2013 (KB3127932) 32-Bit Edition
PATCH-21723Security Update for Microsoft Word 2010 (KB3127953) 32-Bit Edition
PATCH-21732Security Update for Microsoft Office Compatibility Pack Service Pack 3 (KB3127948)
PATCH-21752Security Update for Word Viewer (KB3127962)
PATCH-21736Security Update for Microsoft Office 2007 suites (KB2986253)
PATCH-21741Security Update for Microsoft Office 2010 (KB3115120) 64-Bit Edition
PATCH-21740Security Update for Microsoft Office 2010 (KB3115120) 32-Bit Edition
PATCH-21747Security Update for Microsoft Office 2013 (KB3115153) 64-Bit Edition
PATCH-21746Security Update for Microsoft Office 2013 (KB3115153) 32-Bit Edition
PATCH-21751Security Update for Microsoft Office 2016 (KB3115135) 64-Bit Edition
PATCH-21750Security Update for Microsoft Office 2016 (KB3115135) 32-Bit Edition

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234