cbcvebase.
CVE-2016-0183
published 2016-05-11

CVE-2016-0183: The Windows font library in Microsoft Office 2010 SP2, Word 2010 SP2, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2…

PriorityP357high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
15.70%
96.5th percentile
The Windows font library in Microsoft Office 2010 SP2, Word 2010 SP2, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Microsoft Office Graphics RCE Vulnerability."

Affected

12 ranges
VendorProductVersion rangeFixed in
microsoftoffice
microsoftoffice_web_apps
microsoftsharepoint_server
microsoftword
msrcmicrosoft_office_2007_service_pack_3
msrcmicrosoft_office_2010_service_pack_2
msrcmicrosoft_office_compatibility_pack_service_pack_3
msrcmicrosoft_office_web_apps_2010_service_pack_2
msrcmicrosoft_office_word_viewer
msrcmicrosoft_word_2007_service_pack_3
msrcmicrosoft_word_2010_service_pack_2
msrcword_automation_services_on_microsoft_sharepoint_server_2010_service_pack_2

Detection & IOCsextracted from sources · hover to see the quote

  • Attack vector involves crafted Office documents (e.g., RTF) with specially crafted embedded fonts delivered via email attachment or web-based lure; monitor for Office processes spawning unexpected child processes after opening such documents.
  • The Preview Pane is an attack vector for products rated Critical; monitor for exploitation attempts triggered without explicit file open actions in Office applications.
  • Workaround registry key for Office 2010: block RTF files via HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Security\FileBlock with RtfFiles DWORD=2; absence of this key on unpatched systems indicates exposure.
  • Workaround registry key for Office 2007: block RTF files via HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\12.0\Word\Security\FileOpenBlock with RtfFiles DWORD=1; absence indicates exposure.
  • Workaround registry key for Office 2013: block RTF files via HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word\Security\FileBlock with RtfFiles DWORD=2; absence indicates exposure.
  • ·Exploit status is not publicly disclosed or actively exploited at time of advisory publication; exploitation assessed as 'Less Likely' for older software releases.
  • ·Update 3115121 only applies to specific configurations of Microsoft Office 2010; not all Office 2010 installs will be offered the patch, requiring manual verification of applicability.
  • ·The vulnerability resides in the Windows font library's handling of embedded fonts within Office documents; the fix corrects how the library processes these fonts.

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc8.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.