vendor:
Office Word
by:
Francis Provencher
7,8
CVSS
HIGH
Memory Re-allocation
119
CWE
Product Name: Office Word
Affected Version From: Microsoft Office Word 2013
Affected Version To: Microsoft Office Word 2016
Patch Exists: YES
Related CWE: CVE-2016-3316
CPE: a:microsoft:office
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, OSX
2016
Microsoft Office Word Vulnerability
The specific flaw exists within the parsing of invalid operand in “sprmSdyaTop” into a SEPX structure. An attacker can use this flaw to re-allocate memory and execute arbitrary code under the context of the current process.
Mitigation:
Microsoft fixed the issue (MS16-099)