First published: Wed May 11 2016(Updated: )
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2010-sp2 | |
Microsoft Office | =2010-sp2 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 | |
Microsoft Office Word | =2007-sp3 | |
Microsoft Office Word | =2010-sp2 | |
Microsoft Office Word | =2013-sp1 | |
Microsoft Office Word | =2013-sp1 | |
Microsoft Office Word | =2016 | |
Microsoft Word | =2011 | |
Microsoft Word | =2016 | |
Microsoft Office Word Viewer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0198 is rated as critical due to its potential for remote code execution.
To fix CVE-2016-0198, update to the latest version of Microsoft Office as provided in the security bulletin.
CVE-2016-0198 affects various Microsoft Office versions including Word 2007, 2010, 2013, and 2016 across different platforms.
Yes, CVE-2016-0198 can be exploited remotely via a specially crafted Office document.
Exploitation of CVE-2016-0198 can lead to arbitrary code execution on the affected system, potentially compromising it.