CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

CVE-2016-3313 Microsoft Office Remote Code Execution Vulnerabilities (MS16-099)漏洞银行丨0day Bank

2016年8月10日 3183点热度 0人点赞 0条评论

漏洞信息

- Multiple remote code execution vulnerabilities exist in Microsoft Office software when the Office software fails to properly handle objects in memory.

- An information disclosure vulnerability exists when Microsoft OneNote improperly discloses its memory contents.

Microsoft has released a security update that addresses the vulnerabilities by correcting how:
- Office handles objects in memory
- Certain functions handle objects in memory
- Windows validates input before loading libraries

漏洞危害

The most severe of the vulnerabilities could allow remote code execution if a user opens a specially crafted Microsoft Office file. An attacker who successfully exploited the vulnerabilities could run arbitrary code in the context of the current user.

解决方案

Refer to MS16-099 for more information.

Patch:
Following are links for downloading patches to fix the vulnerabilities:

MS16-099: Microsoft Office 2007 Service Pack 3

MS16-099: Microsoft Office 2007 Service Pack 3

MS16-099: Microsoft OneNote 2007 Service Pack 3

MS16-099: Microsoft Word 2007 Service Pack 3

MS16-099: Microsoft Office 2010 Service Pack 2 (32-bit editions)

MS16-099: Microsoft Office 2010 Service Pack 2 (64-bit editions)

MS16-099: Microsoft Office 2010 Service Pack 2 (32-bit editions)

MS16-099: Microsoft Office 2010 Service Pack 2 (64-bit editions)

MS16-099: Microsoft Office 2010 Service Pack 2 (32-bit editions)

MS16-099: Microsoft Office 2010 Service Pack 2 (64-bit editions)

MS16-099: Microsoft OneNote 2010 Service Pack 2 (32-bit editions)

MS16-099: Microsoft OneNote 2010 Service Pack 2 (64-bit editions)

MS16-099: Microsoft Word 2010 Service Pack 2 (32-bit editions)

MS16-099: Microsoft Word 2010 Service Pack 2 (64-bit editions)

MS16-099: Microsoft Office 2013 Service Pack 1 (32-bit editions)

MS16-099: Microsoft Office 2013 Service Pack 1 (64-bit editions)

MS16-099: Microsoft Office 2013 Service Pack 1 (32-bit editions)

MS16-099: Microsoft Office 2013 Service Pack 1 (64-bit editions)

MS16-099: Microsoft OneNote 2013 Service Pack 1 (32-bit editions)

MS16-099: Microsoft OneNote 2013 Service Pack 1 (64-bit editions)

MS16-099: Microsoft Word 2013 Service Pack 1 (32-bit editions)

MS16-099: Microsoft Word 2013 Service Pack 1 (64-bit editions)

MS16-099: Microsoft Office 2016 (32-bit edition)

MS16-099: Microsoft Office 2016 (64-bit edition)

MS16-099: Microsoft OneNote 2016 (32-bit edition)

MS16-099: Microsoft OneNote 2016 (64-bit edition)

MS16-099: Microsoft Word 2016 (32-bit edition)

MS16-099: Microsoft Word 2016 (64-bit edition)

MS16-099: Microsoft Word Viewer

MS16-099: Microsoft Word Viewer

MS16-099: Microsoft Outlook 2007 Service Pack 3

MS16-099: Microsoft Outlook 2010 Service Pack 2 (32-bit editions)

MS16-099: Microsoft Outlook 2010 Service Pack 2 (64-bit editions)

MS16-099: Microsoft Outlook 2013 Service Pack 1 (32-bit editions)

MS16-099: Microsoft Outlook 2013 Service Pack 1 (64-bit editions)

MS16-099: Microsoft Outlook 2016 (32-bit edition)

MS16-099: Microsoft Outlook 2016 (64-bit edition)

www.0daybank.org

标签: 暂无
最后更新:2016年10月22日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me