MS Word RCE via Malicious OLE File
CVE-2022-41061 Published on November 9, 2022
Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
Weakness Type
What is a Code Injection Vulnerability?
The software constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVE-2022-41061 has been classified to as a Code Injection vulnerability or weakness.
Products Associated with CVE-2022-41061
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft SharePoint Server Subscription Edition Language Pack:- Version 16.0.0 and below 16.0.15601.20238 is affected.
- Version 16.0.0 and below 16.0.15601.20238 is affected.
- Version 16.0.1 and below 16.0.10392.20000 is affected.
- Version 16.0.1 and below https://aka.ms/OfficeSecurityReleases is affected.
- Version 16.0.1 and below 16.0.5369.1000 is affected.
- Version 16.0.0 and below 16.0.10392.20000 is affected.
- Version 16.0.0 and below 16.0.5369.1000 is affected.
- Version 16.0.1 and below 16.67.22111300 is affected.
- Version 15.0.0 and below 15.0.5501.1000 is affected.
- Version 16.0.0 and below 16.67.22111300 is affected.
- Version 15.0.1 and below 15.0.5501.1000 is affected.
- Version 15.0.1 and below 15.0.5501.1000 is affected.
- Version 15.0.1 and below 15.0.5501.1000 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.