First published: Wed Jul 13 2016(Updated: )
Microsoft Outlook 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Outlook | =2010-sp2 | |
Microsoft Outlook | =2013-sp1 | |
Microsoft Outlook | =2016 | |
Microsoft Outlook 2013 RT | =2013-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3278 is classified as critical due to its ability to allow remote code execution.
To fix CVE-2016-3278, install the latest security update provided by Microsoft for your version of Outlook.
CVE-2016-3278 affects Microsoft Outlook 2010 SP2, 2013 SP1, and 2016, as well as Outlook RT 2013 SP1.
Yes, CVE-2016-3278 can be exploited by attackers using crafted Office documents.
CVE-2016-3278 is classified as a memory corruption vulnerability affecting Microsoft Office.