Information Disclosure Vulnerability in Microsoft Word Products
CVE-2016-7290

7.1HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
20 December 2016

Summary

Certain Microsoft Word products and services are vulnerable to exploitation through specially crafted documents, which can allow attackers to access sensitive information stored in memory or to trigger a denial of service due to out-of-bounds read. This weakness highlights the importance of updating software to the latest versions and applying security patches to prevent unauthorized access and data leaks.

References

EPSS Score

9% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.