First published: Wed Sep 14 2016(Updated: )
Microsoft PowerPoint 2007 SP3, PowerPoint 2010 SP2, PowerPoint 2013 SP1, PowerPoint 2013 RT SP1, PowerPoint 2016 for Mac, Office Compatibility Pack SP3, PowerPoint Viewer, SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 | |
Microsoft Office Web Apps | =2010-sp2 | |
Microsoft Office Web Apps Server 2013 | =2013-sp1 | |
Microsoft PowerPoint 2010 | =2007-sp3 | |
Microsoft PowerPoint 2010 | =2010-sp2 | |
Microsoft PowerPoint 2010 | =2013-sp1 | |
Microsoft PowerPoint 2010 | =2013-sp1 | |
Microsoft PowerPoint | =2016 | |
Microsoft Office PowerPoint Viewer | ||
Microsoft SharePoint Designer 2013 | =2013-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3360 has a severity rating that indicates a critical vulnerability allowing remote code execution.
To fix CVE-2016-3360, apply the latest updates and security patches provided by Microsoft for the affected software versions.
CVE-2016-3360 affects several versions of Microsoft PowerPoint, Office Compatibility Pack, and Office Web Apps, among others.
Yes, CVE-2016-3360 can be exploited remotely by attackers to execute arbitrary code on vulnerable systems.
While the recommended solution is applying patches, users may temporarily disable certain functionalities in affected applications as a workaround.