First published: Wed Sep 14 2016(Updated: )
The Click-to-Run (C2R) implementation in Microsoft Office 2013 SP1 and 2016 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "Microsoft APP-V ASLR Bypass."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2013-sp1 | |
Microsoft Office | =2016 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0137 is rated as important due to its potential to allow local users to bypass security mechanisms.
To fix CVE-2016-0137, apply the security updates provided by Microsoft for Office 2013 SP1 and 2016.
CVE-2016-0137 affects local users running Microsoft Office 2013 SP1 and Microsoft Office 2016.
CVE-2016-0137 allows an attacker to bypass the Address Space Layout Randomization (ASLR) protection mechanism.
Yes, CVE-2016-0137 specifically affects Microsoft Office versions 2013 SP1 and 2016.