ZeroHour

CVE-2016-7193

KEVmass

Memory Corruption RCE in Microsoft Word and Office Components via Crafted RTF Files

CISA: Microsoft Office Memory Corruption Vulnerability

CVSS 3.1
7.8 high
EPSS
58%p99
Published
()
KEV added
AI analysis

Microsoft Word and several related Office components contain a memory corruption flaw (CWE-119) in their handling of Rich Text Format (RTF) documents. An attacker triggers it by persuading a user to open a specially crafted RTF file, typically delivered as an email attachment, which corrupts memory and permits arbitrary code execution in the context of the current user (CVSS 3.1: 7.8, with user interaction required). The affected footprint is unusually broad, spanning Word 2007 SP2 through Word 2016 on Windows, Word for Mac 2011 and 2016, Word Viewer, the Office Compatibility Pack, Word Automation Services in SharePoint 2010/2013, and Office Web Apps/Office Online Server. The vulnerability is listed in the CISA Known Exploited Vulnerabilities catalog (added 2022-03-03) and carries an EPSS of 57.7 percent (99th percentile), indicating active in-the-wild exploitation; Microsoft addressed it in its November 2016 security updates.

What to do: Apply Microsoft's security updates for every affected component per vendor instructions, which is the required action in CISA's KEV catalog. Because exploitation occurs via malicious RTF files, consider blocking or sandboxing RTF email attachments and opening them in a protected/isolated mode until patches are deployed. Audit for legacy and easily overlooked components, including Word Viewer, the Office Compatibility Pack, Office Web Apps 2010/2013, SharePoint Word Automation Services, and Office Online Server, and upgrade or decommission any that remain unpatched.

Affected
Microsoft Word2007 SP2
Microsoft Office2010 SP2
Microsoft Word2013 SP1
Microsoft Word2013 RT SP1
Microsoft Word2016
Microsoft Word for Mac2011
Microsoft Word for Mac2016
Microsoft Office Compatibility PackSP3
Microsoft Word Viewer
Microsoft Word Automation Services on SharePoint Server 2010SP2
Microsoft Word Automation Services on SharePoint Server 2013SP1
Microsoft Office Web Apps 2010SP2
Estimated exposure
masshundreds of millions of Office/Word installations worldwide (order of magnitude 10^8) — Word ships by default in Microsoft Office, the dominant desktop productivity suite whose user base Microsoft has reported at over a billion people, and the inclusion of server-side components (Office Web Apps, Office Online Server,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, Office Web Apps Server 2013 SP1, and Office Online Server allow remote attackers to execute arbitrary code via a crafted RTF document, aka "Microsoft Office Memory Corruption Vulnerability."

CISA Known Exploited Vulnerability
Affected
Microsoft Office
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
office, office compatibility pack, word, word viewer
Weakness
CWE-119
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news