CVE-2016-7193
KEVmassMemory Corruption RCE in Microsoft Word and Office Components via Crafted RTF Files
CISA: Microsoft Office Memory Corruption Vulnerability
Microsoft Word and several related Office components contain a memory corruption flaw (CWE-119) in their handling of Rich Text Format (RTF) documents. An attacker triggers it by persuading a user to open a specially crafted RTF file, typically delivered as an email attachment, which corrupts memory and permits arbitrary code execution in the context of the current user (CVSS 3.1: 7.8, with user interaction required). The affected footprint is unusually broad, spanning Word 2007 SP2 through Word 2016 on Windows, Word for Mac 2011 and 2016, Word Viewer, the Office Compatibility Pack, Word Automation Services in SharePoint 2010/2013, and Office Web Apps/Office Online Server. The vulnerability is listed in the CISA Known Exploited Vulnerabilities catalog (added 2022-03-03) and carries an EPSS of 57.7 percent (99th percentile), indicating active in-the-wild exploitation; Microsoft addressed it in its November 2016 security updates.
What to do: Apply Microsoft's security updates for every affected component per vendor instructions, which is the required action in CISA's KEV catalog. Because exploitation occurs via malicious RTF files, consider blocking or sandboxing RTF email attachments and opening them in a protected/isolated mode until patches are deployed. Audit for legacy and easily overlooked components, including Word Viewer, the Office Compatibility Pack, Office Web Apps 2010/2013, SharePoint Word Automation Services, and Office Online Server, and upgrade or decommission any that remain unpatched.
| Microsoft Word | 2007 SP2 |
| Microsoft Office | 2010 SP2 |
| Microsoft Word | 2013 SP1 |
| Microsoft Word | 2013 RT SP1 |
| Microsoft Word | 2016 |
| Microsoft Word for Mac | 2011 |
| Microsoft Word for Mac | 2016 |
| Microsoft Office Compatibility Pack | SP3 |
| Microsoft Word Viewer | — |
| Microsoft Word Automation Services on SharePoint Server 2010 | SP2 |
| Microsoft Word Automation Services on SharePoint Server 2013 | SP1 |
| Microsoft Office Web Apps 2010 | SP2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, Office Web Apps Server 2013 SP1, and Office Online Server allow remote attackers to execute arbitrary code via a crafted RTF document, aka "Microsoft Office Memory Corruption Vulnerability."
- Affected
- Microsoft Office
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- office, office compatibility pack, word, word viewer
- Weakness
- CWE-119
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H