CVE-2016-7275Improper Restriction of Operations within the Bounds of a Memory Buffer in Microsoft Office

Severity
7.8HIGHNVD
EPSS
0.8%
top 25.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 20
Latest updateMay 14

Description

Microsoft Office 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 mishandles library loading, which allows local users to gain privileges via a crafted application, aka "Microsoft Office OLE DLL Side Loading Vulnerability."

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

🔴Vulnerability Details

1
GHSA
GHSA-w8vw-phcw-9mh5: Microsoft Office 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 mishandles library loading, which allows local users to gain privileges via a crafted appli2022-05-14

📋Vendor Advisories

2
Red Hat
ImageMagick: Memory allocation failure in AcquireMagickMemory (incomplete fix for CVE-2016-8866)2017-03-27
Microsoft
Microsoft Office Remote Code Execution Vulnerability2016-12-13

🕵️Threat Intelligence

8
Trendmicro
March 2017 Patch Tuesday: 18 Security Bulletins2017-03-15
Trendmicro
March 2017 Patch Tuesday: 18 Security Bulletins2017-03-15
Trendmicro
March 2017 Patch Tuesday: 18 Security Bulletins2017-03-15
Trendmicro
March 2017 Patch Tuesday: 18 Security Bulletins2017-03-15
Trendmicro
March 2017 Patch Tuesday: 18 Security Bulletins2017-03-15

💬Community

2
Bugzilla
CVE-2017-7275 ImageMagick: Memory allocation failure in AcquireMagickMemory (incomplete fix for CVE-2016-8866) [fedora-all]2017-03-31
Bugzilla
CVE-2017-7275 ImageMagick: Memory allocation failure in AcquireMagickMemory (incomplete fix for CVE-2016-8866)2017-03-31