CVE-2017-0019: Buffer Overflow
Published Mar 17, 2017
·Updated
Microsoft Word 2016 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0006, CVE-2017-0020, CVE-2017-0030, CVE-2017-0031, CVE-2017-0052, and CVE-2017-0053.
Affected Software
1 affected component
Microsoft Word=2016
Remediation
Event History
Mar 17, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-0019?
CVE-2017-0019 has a critical severity rating as it allows remote attackers to execute arbitrary code.
2
How do I fix CVE-2017-0019?
To fix CVE-2017-0019, install the latest Microsoft Office security updates.
3
What versions of Microsoft Word are affected by CVE-2017-0019?
CVE-2017-0019 affects Microsoft Word 2016 specifically.
4
Can CVE-2017-0019 lead to a denial of service?
Yes, CVE-2017-0019 can cause a denial of service due to memory corruption.
5
Are there any known exploits for CVE-2017-0019?
Yes, there are known exploits that utilize crafted documents to leverage CVE-2017-0019.