CVE-2022-41060
published 2022-11-09CVE-2022-41060: Microsoft Word Information Disclosure Vulnerability
PriorityP420medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.74%
50.6th percentile
Microsoft Word Information Disclosure Vulnerability
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2021 | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_online_server | >= 16.0.1 < 16.0.10392.20000 | 16.0.10392.20000 |
| microsoft | microsoft_office_web_apps_server_2013_service_pack_1 | >= 15.0.1 < 15.0.5501.1000 | 15.0.5501.1000 |
| microsoft | microsoft_sharepoint_enterprise_server_2013_service_pack_1 | >= 15.0.0 < 15.0.5501.1000 | 15.0.5501.1000 |
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < 16.0.5369.1000 | 16.0.5369.1000 |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < 16.0.10392.20000 | 16.0.10392.20000 |
| microsoft | microsoft_word_2013_service_pack_1 | >= 15.0.1 < 15.0.5501.1000 | 15.0.5501.1000 |
| microsoft | microsoft_word_2016 | >= 16.0.1 < 16.0.5369.1000 | 16.0.5369.1000 |
| microsoft | office | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| microsoft | office_web_apps_server | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server_subscription_edition_language_pack | >= 16.0.0 < 16.0.15601.20238 | 16.0.15601.20238 |
| microsoft | word | — | — |
| microsoft | word | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_64-bit_editions | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Word up to Office Online Server information disclosure
vuldb·2026-05-19·CVSS 5.5
CVE-2022-41060 [MEDIUM] Microsoft Word up to Office Online Server information disclosure
A vulnerability identified as problematic has been detected in Microsoft Word 2013 SP1/2013 RT SP1/2016/2019/Office Online Server. The affected element is an unknown function. The manipulation leads to information disclosure.
This vulnerability is documented as CVE-2022-41060. The attack can be initiated remotely. There is not any exploit available.
To fix this issue, it is recommended to deploy a patch.
GHSA
GHSA-pfqx-9x47-5fp2: Microsoft Word Information Disclosure Vulnerability
ghsa_unreviewed·2022-11-10·CVSS 5.5
CVE-2022-41060 [MEDIUM] GHSA-pfqx-9x47-5fp2: Microsoft Word Information Disclosure Vulnerability
Microsoft Word Information Disclosure Vulnerability. This CVE ID is unique from CVE-2022-41103.
GHSA
GHSA-6f22-3fg3-w86j: Microsoft Word Information Disclosure Vulnerability
ghsa_unreviewed·2022-11-10·CVSS 5.5
CVE-2022-41103 [MEDIUM] GHSA-6f22-3fg3-w86j: Microsoft Word Information Disclosure Vulnerability
Microsoft Word Information Disclosure Vulnerability. This CVE ID is unique from CVE-2022-41060.
Microsoft
Microsoft Word Information Disclosure Vulnerability
vendor_msrc·2022-11-08·CVSS 5.5
CVE-2022-41060 [MEDIUM] Microsoft Word Information Disclosure Vulnerability
Microsoft Word Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is memory layout - the vulnerability allows an attacker to collect information that facilitates predicting addressing of the memory.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
Exploitation of the vulnerability requires that a user open a specially crafted file.
In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file.
In a web-based attack scenario, an attacker could host a website (or
No detection rules found.
No public exploits indexed.
2022-11-09
Published