Remote Code Execution Vulnerability in Microsoft Publisher 2010 SP2
CVE-2016-7289

7.8HIGH

Key Information:

Vendor

Microsoft

Status
Vendor
CVE Published:
20 December 2016

What is CVE-2016-7289?

Microsoft Publisher 2010 SP2 is susceptible to a vulnerability that allows remote attackers to execute arbitrary code or induce a denial of service through specially crafted documents. This flaw highlights the risks of opening untrusted files and emphasizes the importance of keeping software updated to mitigate potential attacks.

References

EPSS Score

33% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2016-7289 : Remote Code Execution Vulnerability in Microsoft Publisher 2010 SP2