CVE-2022-41107: Microsoft Office Graphics Remote Code Execution Vulnerability
Published Nov 8, 2022
·Updated
Microsoft Office Graphics Remote Code Execution Vulnerability
Affected Software
15 affected componentsFixes available
Microsoft 365 Apps
Microsoft Office=2019
Microsoft Office Macos=2019
Microsoft Office=2021
Microsoft Office Macos=2021
Microsoft Office Long Term Servicing Channel=2021
Microsoft Office Long Term Servicing Channel Macos=2021
Microsoft Office LTSC 2021 for 32-bit editions<https://aka.ms/OfficeSecurityReleases
https://aka.ms/OfficeSecurityReleases
Microsoft Office LTSC for Mac 2021<16.67.22111300
16.67.22111300
Microsoft 365 Apps for Enterprise<https://aka.ms/OfficeSecurityReleases
https://aka.ms/OfficeSecurityReleases
Microsoft Office LTSC 2021 for 64-bit editions<https://aka.ms/OfficeSecurityReleases
https://aka.ms/OfficeSecurityReleases
Microsoft Office 2019 for 32-bit editions<https://aka.ms/OfficeSecurityReleases
https://aka.ms/OfficeSecurityReleases
Microsoft Office 2019 for 64-bit editions<https://aka.ms/OfficeSecurityReleases
https://aka.ms/OfficeSecurityReleases
Microsoft Office 2019 for Mac<16.67.22111300
16.67.22111300
Microsoft 365 Apps for Enterprise<https://aka.ms/OfficeSecurityReleases
https://aka.ms/OfficeSecurityReleases
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.67.22111300
Event History
Nov 8, 2022
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
Description
Nov 9, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·10:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-41107?
The severity of CVE-2022-41107 is high with a CVSS score of 7.8.
2
What is the affected software for CVE-2022-41107?
The affected software for CVE-2022-41107 includes Microsoft Office LTSC for Mac 2021, Microsoft Office 2019, and Microsoft Office 2021.
3
How can I fix CVE-2022-41107?
To fix CVE-2022-41107, Microsoft has released security updates for affected software. Please refer to the vendor's website for the appropriate updates.
4
Where can I find more information about CVE-2022-41107?
You can find more information about CVE-2022-41107 on the Microsoft Security Response Center website.