CVE-2016-0022: Buffer Overflow
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps Server 2013 SP1, and SharePoint Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0052.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0022?
CVE-2016-0022 is classified as a critical vulnerability.
How do I fix CVE-2016-0022?
To fix CVE-2016-0022, apply the latest security updates provided by Microsoft for the affected applications.
Which Microsoft products are affected by CVE-2016-0022?
CVE-2016-0022 affects Microsoft Word 2007, 2010, 2013, 2016, and various versions for Mac and other Microsoft Office products.
Can CVE-2016-0022 lead to remote code execution?
Yes, CVE-2016-0022 can allow an attacker to execute remote code on an affected system.
Is there a workaround for CVE-2016-0022?
Currently, the recommended approach for CVE-2016-0022 is to install the security update rather than relying on workarounds.