First published: Thu Jun 16 2016(Updated: )
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to obtain sensitive information from process memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2010-sp2 | |
Microsoft Office | =2010-sp2 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 | |
Microsoft Office Web Apps | =2010-sp2 | |
Microsoft Office Web Apps | =2013-sp1 | |
Microsoft SharePoint Server 2010 | =2010-sp2 | |
Microsoft SharePoint Server 2010 | =2013-sp1 | |
Microsoft Office Word | =2007-sp3 | |
Microsoft Office Word | =2010-sp2 | |
Microsoft Office Word Viewer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3234 is rated as Important by Microsoft, indicating a significant risk to affected systems.
To fix CVE-2016-3234, apply the latest security updates provided by Microsoft for the affected software versions.
CVE-2016-3234 affects Microsoft Word 2007 SP3, Office 2010 SP2, Office Compatibility Pack SP3, and certain versions of SharePoint Server and Office Web Apps.
Yes, CVE-2016-3234 can be exploited remotely by attackers to execute arbitrary code on the affected systems.
There are no known workarounds for CVE-2016-3234, so it's crucial to apply the provided updates immediately.