Overview
- Description
- Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "Word RTF 'listoverridecount' Remote Code Execution Vulnerability."
- Source
- secure@microsoft.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 9.3
- Impact score
- 10
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:C/I:C/A:C
Known exploits
Data from CISA
- Vulnerability name
- Microsoft Word Remote Code Execution Vulnerability
- Exploit added on
- Mar 28, 2022
- Exploit action due
- Apr 18, 2022
- Required action
- Apply updates per vendor instructions.
Weaknesses
- nvd@nist.gov
- CWE-787
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:microsoft:office_compatibility_pack:-:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "55AA5CC4-AF80-49A2-ACD1-5644AA971044" }, { "criteria": "cpe:2.3:a:microsoft:office_compatibility_pack:-:sp3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "71AF058A-2E5D-4B11-88DB-8903C64B13C1" }, { "criteria": "cpe:2.3:a:microsoft:office_web_apps:2010:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "343EEB54-C1B1-4D7B-8780-5B5A5F2F840C" }, { "criteria": "cpe:2.3:a:microsoft:office_word_viewer:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C64B2636-8F96-48BA-921F-A8FA0E62DE63" }, { "criteria": "cpe:2.3:a:microsoft:sharepoint_server:2010:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DCBCB0A0-BC40-4E6B-BD06-A137BB964B7F" }, { "criteria": "cpe:2.3:a:microsoft:word:2003:sp3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "80F8E09E-E7F7-4D86-B140-3933EDC54E1C" }, { "criteria": "cpe:2.3:a:microsoft:word:2007:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "262BC12C-246A-41AB-A08D-3D205156F074" }, { "criteria": "cpe:2.3:a:microsoft:word:2007:sp3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7D006508-BFB0-4F21-A361-3DA644F51D8A" }, { "criteria": "cpe:2.3:a:microsoft:word:2010:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D2A0758C-6499-407F-823A-6F28BE56805E" } ], "operator": "OR" } ] } ]