CVE-2022-41060: Microsoft Word Information Disclosure Vulnerability
Microsoft Word Information Disclosure Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.5501.1000Patch KB5002217 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5369.1000Patch KB5002305 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.5501.1000Patch KB5002261 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10392.20000Patch KB5002294 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.5501.1000Patch KB5002235 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5369.1000Patch KB5002223 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10392.20000Patch KB5002276 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.15601.20238Patch KB5002291
Event History
Frequently Asked Questions
What is CVE-2022-41060?
CVE-2022-41060 is a vulnerability in Microsoft Word that allows for information disclosure.
How severe is CVE-2022-41060?
CVE-2022-41060 has a severity rating of 5.5, which is considered high.
Which software products are affected by CVE-2022-41060?
The following products are affected by CVE-2022-41060: SharePoint Enterprise Server 2016, Office LTSC 2021 for 64-bit editions, Office Online Server, Word 2013, Word 2016, Word 2013 RT, SharePoint Enterprise Server 2013, Office Web Apps Server 2013, SharePoint Server Subscription Edition Language Pack, SharePoint Server 2019, Office 2019 for 32-bit editions, Office 2019 for 64-bit editions, Office LTSC 2021 for 32-bit editions, 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Microsoft Office, Microsoft Office Online Server, Microsoft Office Web Apps Server, Microsoft SharePoint Enterprise Server, Microsoft SharePoint Server, and Microsoft Word.
How can I fix CVE-2022-41060?
To fix CVE-2022-41060, apply the relevant patches or updates provided by Microsoft for the affected software products.
Where can I find more information about CVE-2022-41060?
More information about CVE-2022-41060 can be found at the Microsoft Security Response Center: [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41060](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41060)