CVE-2022-24511
published 2022-03-09CVE-2022-24511: Microsoft Office Word Tampering Vulnerability Microsoft Office Word Tampering Vulnerability
medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
1.02%
59.9th percentile
Microsoft Office Word Tampering Vulnerability
Microsoft Office Word Tampering Vulnerability
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2019_for_mac | >= 16.0.0 < 16.59.22031300 | 16.59.22031300 |
| microsoft | microsoft_office_ltsc_2021 | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_for_mac_2021 | >= 16.0.1 < 16.59.22031300 | 16.59.22031300 |
| microsoft | microsoft_word_2013_service_pack_1 | >= 15.0.1 < 15.0.5431.1000 | 15.0.5431.1000 |
| microsoft | microsoft_word_2016 | >= 16.0.1 < 16.0.5290.1000 | 16.0.5290.1000 |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | microsoft_office_2019_for_mac | — | — |
| msrc | microsoft_office_ltsc_2021_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_for_mac_2021 | — | — |
| msrc | microsoft_word_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_word_2013_service_pack_1 | — | — |
| msrc | microsoft_word_2016 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
cvelistv55.5MEDIUM
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Office up to LTSC 2021 Word
vuldb·2026-05-19·CVSS 5.5
CVE-2022-24511 [MEDIUM] Microsoft Office up to LTSC 2021 Word
A vulnerability categorized as problematic has been discovered in Microsoft Office up to LTSC 2021. This issue affects some unknown processing of the component Word. Executing a manipulation can lead to an unknown weakness.
This vulnerability is registered as CVE-2022-24511. It is possible to launch the attack remotely. No exploit is available.
Applying a patch is advised to resolve this issue.
CVEList
Microsoft Office Word Tampering Vulnerability
cvelistv5·2022-03-09·CVSS 5.5
CVE-2022-24511 [MEDIUM] Microsoft Office Word Tampering Vulnerability
Microsoft Office Word Tampering Vulnerability
Microsoft Office Word Tampering Vulnerability
Microsoft
Microsoft Office Word Tampering Vulnerability
vendor_msrc·2022-03-08·CVSS 5.5
CVE-2022-24511 [MEDIUM] Microsoft Office Word Tampering Vulnerability
Microsoft Office Word Tampering Vulnerability
FAQ: If the preview pane is an attack vector, why is the severity for this vulnerability Important and not Critical?
Even though the preview pane is an attack vector, the attacker cannot achieve remote code execution if they successfully exploit the vulnerability, but can only gain information from the victim.
FAQ: Are the updates for the Microsoft Office for Mac currently available?
The security update for Microsoft Office 2019 for Mac and Microsoft Office LTSC for Mac 2021 are not immediately available. The updates will be released as soon as possible, and when they are available, customers will be notified via a revision to this CVE information.
Microsoft Office Word: Microsoft Office Word
Microsoft: Microsoft
Customer Action Required:
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-03-09
Published