First published: Wed Jan 10 2018(Updated: )
Microsoft Word 2016 in Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0794.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office for Mac OS X | =2016 | |
Microsoft Office | =2016-c2r | |
Microsoft Office Online Server | =2016 | |
Microsoft SharePoint Server | =2016 | |
Microsoft Word for Android | =2016 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0792 has a critical severity rating due to its potential for remote code execution.
To mitigate CVE-2018-0792, it is recommended to apply the latest security updates issued by Microsoft.
CVE-2018-0792 affects Microsoft Office 2016, Microsoft Word 2016, Microsoft Office Online Server 2016, and SharePoint Server 2016.
Yes, CVE-2018-0792 enables an attacker to execute arbitrary code if a victim opens a specially crafted document.
Yes, disabling the automatic execution of macros in Microsoft Word can serve as a temporary workaround for CVE-2018-0792.