← Back

CVE-2016-7290

nvd nist
Published: Dec 20, 2016Modified: May 6, 2026

JSON object

Loading...
7.1
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Exploitability: 1.8 / Impact: 5.2
Source: NVD

Description

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office Information Disclosure Vulnerability," a different vulnerability than CVE-2016-7291.

Affected (8)

7 products
Office
Office Compatibility Pack
Office Web Apps
Sharepoint Server
Word
Word Automation Services
Word For Mac
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Version 2010 sp2
All versions
Version 2010 sp2
Version 2010 sp2
Microsoft
Version 2007 sp3
Version 2010 sp2
All versions
Version 2011

References (6)

Source: secure@microsoft.com
Third Party AdvisoryVDB Entry
Source: secure@microsoft.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.