CVE-2022-41061: Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.5501.1000Patch KB5002217 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.5501.1000Patch KB5002235 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5369.1000Patch KB5002223 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5369.1000Patch KB5002305 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.67.22111300 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10392.20000Patch KB5002294 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.5501.1000Patch KB5002261 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.15601.20238Patch KB5002291 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10392.20000Patch KB5002276 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.15601.20238Patch KB5002296
Event History
Frequently Asked Questions
What is CVE-2022-41061?
CVE-2022-41061 is a vulnerability in Microsoft Word that allows remote code execution.
How severe is CVE-2022-41061?
CVE-2022-41061 has a severity rating of 7.8, which is considered high.
Which products are affected by CVE-2022-41061?
The affected products include Microsoft 365 Apps for Enterprise, Microsoft Word 2016, Microsoft Office 2019 for Mac, Microsoft Word 2013, SharePoint Enterprise Server 2016, and others. For a complete list, refer to the vendor's security advisory.
How can I fix CVE-2022-41061?
To fix CVE-2022-41061, apply the available patches or updates provided by Microsoft. Refer to the vendor's security advisory for specific remediation steps for each affected product.
Where can I find more information about CVE-2022-41061?
You can find more information about CVE-2022-41061 on the Microsoft Security Response Center website.