First published: Wed Jul 13 2016(Updated: )
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2010-sp2 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 | |
Microsoft Office Word | =2007-sp3 | |
Microsoft Office Word | =2010-sp2 | |
Microsoft Office Word | =2013-sp1 | |
Microsoft Word | =2011 | |
Microsoft Word | =2016 | |
Microsoft Office 2013 RT | =2013-sp1 | |
Microsoft Office Word Viewer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3280 is classified as critical due to its potential for remote code execution.
To fix CVE-2016-3280, users should apply the latest security updates provided by Microsoft for the affected versions of Office and Word.
CVE-2016-3280 affects Microsoft Office 2007 SP3, Office 2010 SP2, Word 2013 SP1, Word for Mac 2011, and other specified versions.
CVE-2016-3280 can be exploited by remote attackers through a specially crafted Office document that executes arbitrary code.
There is no official workaround for CVE-2016-3280; applying the security update is the recommended action.