CVE-2022-22004: Microsoft Office ClickToRun Remote Code Execution Vulnerability
Published Feb 8, 2022
·Updated
Microsoft Office ClickToRun Remote Code Execution Vulnerability
Affected Software
8 affected componentsFixes available
Microsoft Office 2013 Click-to-Run (C2R) for 64-bit editions
Microsoft Office 2013 Click-to-Run (C2R) for 32-bit editions
Microsoft 365 Apps for Enterprise
Microsoft 365 Apps for Enterprise
Microsoft 365 Apps
Microsoft 365 Apps
Microsoft Office=2013
Microsoft Office=2013
Event History
Feb 8, 2022
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
Description
Feb 9, 2022
CVE Published
via MITRE·04:36 PM
Data Sourced
via MITRE·04:36 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2022-22004?
CVE-2022-22004 is a remote code execution vulnerability in Microsoft Office ClickToRun.
2
What is the severity of CVE-2022-22004?
The severity of CVE-2022-22004 is high with a CVSS score of 7.8.
3
Which software is affected by CVE-2022-22004?
Microsoft 365 Apps for Enterprise, Microsoft Office 2013 Click-to-Run, and Microsoft Office LTSC for Mac 2021 are affected by CVE-2022-22004.
4
How can I fix CVE-2022-22004?
You can fix CVE-2022-22004 by applying the security updates provided by Microsoft. Refer to the official Microsoft documentation for more information.
5
Where can I find more information about CVE-2022-22004?
You can find more information about CVE-2022-22004 on the Microsoft Security Response Center website.