First published: Wed Mar 09 2016(Updated: )
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, Office Web Apps 2010 SP2, and Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2010-sp2 | |
Microsoft Office | =2010-sp2 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 | |
Microsoft Office Web Apps Server 2013 | =2010-sp2 | |
Microsoft Office Web Apps Server 2013 | =2013-sp1 | |
Microsoft SharePoint Server 2010 | =2010-sp2 | |
Microsoft SharePoint Server 2010 | =2013-sp1 | |
Microsoft Office Word | =2007-sp3 | |
Microsoft Office Word | =2010-sp2 | |
Microsoft Office Word | =2013-sp1 | |
Microsoft Office Word | =2013-sp1 | |
Microsoft Office Word | =2016 | |
Microsoft Word | =2011 | |
Microsoft Word | =2016 | |
Microsoft Office Word Viewer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0134 has a severity rating of critical due to potential remote code execution vulnerabilities in the affected Microsoft Word products.
To fix CVE-2016-0134, ensure that you install the latest security updates provided by Microsoft for your affected Office applications.
CVE-2016-0134 affects multiple versions of Microsoft Word, Office Compatibility Pack, and SharePoint Server among others.
CVE-2016-0134 is a remote code execution vulnerability that allows attackers to run arbitrary code on the affected systems.
While Microsoft has released patches for CVE-2016-0134, unpatched systems remain at risk and should be updated to avoid exploitation.