CVE-2016-7193
Summary
| CVE | CVE-2016-7193 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-10-14 02:59:00 UTC |
| Updated | 2018-10-12 22:14:00 UTC |
| Description | Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, Office Web Apps Server 2013 SP1, and Office Online Server allow remote attackers to execute arbitrary code via a crafted RTF document, aka "Microsoft Office Memory Corruption Vulnerability." |
Risk And Classification
EPSS: 0.711990000 probability, percentile 0.987020000 (date 2026-04-02)
CISA KEV: Listed on 2022-03-03; due 2022-03-24; ransomware use Unknown
Problem Types: CWE-119
CISA Known Exploited Vulnerability
| Vendor | Microsoft |
|---|---|
| Product | Office |
| Name | Microsoft Office Memory Corruption Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2016-7193 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Office | 2010 | sp2 | All | All |
| Application | Microsoft | Office | 2010 | sp2 | All | All |
| Application | Microsoft | Office Compatibility Pack | - | sp3 | All | All |
| Application | Microsoft | Office Compatibility Pack | - | sp3 | All | All |
| Application | Microsoft | Office Online Server | All | All | All | All |
| Application | Microsoft | Office Online Server | All | All | All | All |
| Application | Microsoft | Office Web Apps | 2010 | sp2 | All | All |
| Application | Microsoft | Office Web Apps | 2010 | sp2 | All | All |
| Application | Microsoft | Office Web Apps Server | 2013 | sp1 | All | All |
| Application | Microsoft | Office Web Apps Server | 2013 | sp1 | All | All |
| Application | Microsoft | Office Word Viewer | - | All | All | All |
| Application | Microsoft | Office Word Viewer | - | All | All | All |
| Application | Microsoft | Sharepoint Server | 2010 | sp2 | All | All |
| Application | Microsoft | Sharepoint Server | 2013 | sp1 | All | All |
| Application | Microsoft | Sharepoint Server | 2010 | sp2 | All | All |
| Application | Microsoft | Sharepoint Server | 2013 | sp1 | All | All |
| Application | Microsoft | Word | 2007 | sp2 | All | All |
| Application | Microsoft | Word | 2013 | sp1 | All | All |
| Application | Microsoft | Word | 2013 | sp1 | All | All |
| Application | Microsoft | Word | 2016 | All | All | All |
| Application | Microsoft | Word | 2007 | sp2 | All | All |
| Application | Microsoft | Word | 2013 | sp1 | All | All |
| Application | Microsoft | Word | 2013 | sp1 | All | All |
| Application | Microsoft | Word | 2016 | All | All | All |
| Application | Microsoft | Word Automation Services | - | All | All | All |
| Application | Microsoft | Word Automation Services | - | All | All | All |
| Application | Microsoft | Word For Mac | 2011 | All | All | All |
| Application | Microsoft | Word For Mac | 2016 | All | All | All |
| Application | Microsoft | Word For Mac | 2011 | All | All | All |
| Application | Microsoft | Word For Mac | 2016 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft Office CVE-2016-7193 Memory Corruption Vulnerability | BID | www.securityfocus.com | |
| Microsoft Office RTF File Processing Flaw Lets Remote Users Execute Arbitrary Code - SecurityTracker | SECTRACK | www.securitytracker.com | |
| Microsoft Security Bulletin MS16-121 - Critical | Microsoft Docs | MS | docs.microsoft.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.