KLA10785
Code execution vulnerability in Microsoft Office
Updated: 06/01/2019
Detect date
?
04/12/2016
Severity
?
High
Description

Multiple unspecified vulnerabilities was found in Microsoft Office. By exploiting this vulnerability malicious users can execute arbitrary code. This vulnerability can be exploited remotely via a specially designed content.


Technical details

You can mitigate this vulnerability via using Microsoft Office File Block Policy. For further details look at original advisory listed below.

Affected products

Microsoft Office 2007 Service Pack 3
Microsoft Office 2010 Service Pack 2
Microsoft Office 2013 Service Pack 1
Microsoft Office 2013 RT Service Pack 1
Microsoft Office 2016
Microsoft Office for Mac 2011
Microsoft Office 2016 for Mac
Microsoft Office Compatibility Pack Service Pack 3
Microsoft Excel Viewer and Word Viewer
Microsoft SharePoint Server 2007 Service Pack 3
Microsoft SharePoint Server 2010 Service Pack 2
Microsoft SharePoint Server 2013 Service Pack 1
Microsoft Office Web Apps 2010
Microsoft Office Web Apps 2013

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2016-0145
CVE-2016-0136
CVE-2016-0139
CVE-2016-0122
CVE-2016-0127

Impacts
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

SB 
[?]

PE 
[?]
Related products
Microsoft Office
CVE-IDS
?
CVE-2016-01459.3Critical
CVE-2016-01369.3Critical
CVE-2016-01399.3Critical
CVE-2016-01229.3Critical
CVE-2016-01279.3Critical
Microsoft official advisories
Microsoft Security Update Guide
KB list

3114994
3114927
3114937
3154208
3142577
3114895
3114987
3114934
3114898
3114888
3114982
3114983
3114871
3114988
3114947
3114892
3114964
3114993
3114897
3114990
3114960
3114985
3114566
3144429
3114944
3144432
3144427
3144428
3114542