CVE-2017-0262: Microsoft Office Remote Code Execution Vulnerability
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0261 and CVE-2017-0281.
Other sources
A remote code execution vulnerability exists in Microsoft Office.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-0262?
CVE-2017-0262 has a critical severity rating as it allows remote code execution.
How do I fix CVE-2017-0262?
To fix CVE-2017-0262, users should apply the latest security updates provided by Microsoft for affected Office versions.
What versions of Microsoft Office are affected by CVE-2017-0262?
CVE-2017-0262 affects Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016.
What type of vulnerability is CVE-2017-0262?
CVE-2017-0262 is classified as a remote code execution vulnerability.
How can CVE-2017-0262 be exploited?
CVE-2017-0262 can be exploited by successfully sending a crafted file to a user, leading to arbitrary code execution.