CVE-2016-0134
Summary
| CVE | CVE-2016-0134 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-03-09 11:59:00 UTC |
| Updated | 2018-10-12 22:11:00 UTC |
| Description | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, Office Web Apps 2010 SP2, and Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability." |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Office | 2010 | sp2 | x64 | All |
| Application | Microsoft | Office | 2010 | sp2 | x86 | All |
| Application | Microsoft | Office | 2010 | sp2 | x64 | All |
| Application | Microsoft | Office | 2010 | sp2 | x86 | All |
| Application | Microsoft | Office Compatibility Pack | All | sp3 | All | All |
| Application | Microsoft | Office Compatibility Pack | All | sp3 | All | All |
| Application | Microsoft | Office Web Apps Server | 2010 | sp2 | All | All |
| Application | Microsoft | Office Web Apps Server | 2013 | sp1 | All | All |
| Application | Microsoft | Office Web Apps Server | 2010 | sp2 | All | All |
| Application | Microsoft | Office Web Apps Server | 2013 | sp1 | All | All |
| Application | Microsoft | Sharepoint Server | 2010 | sp2 | All | All |
| Application | Microsoft | Sharepoint Server | 2013 | sp1 | All | All |
| Application | Microsoft | Sharepoint Server | 2010 | sp2 | All | All |
| Application | Microsoft | Sharepoint Server | 2013 | sp1 | All | All |
| Application | Microsoft | Word | 2007 | sp3 | All | All |
| Application | Microsoft | Word | 2010 | sp2 | All | All |
| Application | Microsoft | Word | 2013 | sp1 | All | All |
| Application | Microsoft | Word | 2013 | sp1 | All | All |
| Application | Microsoft | Word | 2016 | All | All | All |
| Application | Microsoft | Word | 2007 | sp3 | All | All |
| Application | Microsoft | Word | 2010 | sp2 | All | All |
| Application | Microsoft | Word | 2013 | sp1 | All | All |
| Application | Microsoft | Word | 2013 | sp1 | All | All |
| Application | Microsoft | Word | 2016 | All | All | All |
| Application | Microsoft | Word For Mac | 2011 | All | All | All |
| Application | Microsoft | Word For Mac | 2016 | All | All | All |
| Application | Microsoft | Word For Mac | 2011 | All | All | All |
| Application | Microsoft | Word For Mac | 2016 | All | All | All |
| Application | Microsoft | Word Viewer | All | All | All | All |
| Application | Microsoft | Word Viewer | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft Office Bugs Let Remote Users Bypass Code Signing Restrictions and Execute Arbitrary Code - SecurityTracker | SECTRACK | www.securitytracker.com | |
| Microsoft Office CVE-2016-0134 Memory Corruption Vulnerability | BID | www.securityfocus.com | |
| Microsoft Security Bulletin MS16-029 - Important | Microsoft Docs | MS | docs.microsoft.com | |
| Microsoft SharePoint File Processing Flaw Lets Remote Users Execute Arbitrary Code - SecurityTracker | SECTRACK | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.