CVE-2016-0021: Buffer Overflow
Published Mar 9, 2016
·Updated
Microsoft InfoPath 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Affected Software
3 affected components
Microsoft InfoPath=2007-sp3
Microsoft InfoPath=2010-sp2
Microsoft InfoPath=2013-sp1
Event History
Mar 9, 2016
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0021?
CVE-2016-0021 has been assigned a critical severity level due to its potential for remote code execution.
2
How do I fix CVE-2016-0021?
To fix CVE-2016-0021, install the appropriate Microsoft security update provided for your version of InfoPath.
3
Which software versions are affected by CVE-2016-0021?
CVE-2016-0021 affects Microsoft InfoPath 2007 SP3, 2010 SP2, and 2013 SP1.
4
What kind of vulnerability is CVE-2016-0021?
CVE-2016-0021 is classified as a memory corruption vulnerability that allows remote code execution through crafted Office documents.
5
Who can exploit CVE-2016-0021?
Remote attackers can exploit CVE-2016-0021 by sending specially crafted Office documents to vulnerable InfoPath installations.