LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2010-3333: Microsoft Office Stack-based Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2010-3333 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A stack-based buffer overflow vulnerability exists in the parsing of RTF data in Microsoft Office and earlier allows an attacker to perform remote code execution.

CVE-2010-3333 is a stack-based buffer overflow in Microsoft Office that arises when the software parses Rich Text Format (RTF) data. A crafted RTF file can trigger the flaw and allow an attacker to execute code in the context of the user who opens it. Because Office documents are routinely exchanged by email and shared drives, this class of issue has long been a practical path for remote code execution on endpoints. Confirm exact product scope and fixed builds against the vendor advisory.

IT and security teams should treat unpatched Office installations that still handle RTF as a priority for inventory and remediation. Public detail on ransomware use of this specific CVE is not documented; the CISA-required action is to apply updates per vendor instructions.

How it works

The underlying weakness is CWE-119: improper restriction of operations within the bounds of a memory buffer. In this case the overflow is stack-based and occurs during RTF parsing inside Microsoft Office. When a malformed RTF structure is processed, data can overwrite adjacent stack memory. An attacker who controls that data can typically redirect execution flow, leading to arbitrary code running with the privileges of the logged-on user.

Abuse generally requires the victim to open or preview a malicious RTF document. Delivery is commonly via email attachment, file share, or other document-exchange channels. No further exploit mechanics are stated in the provided facts; treat any public proof-of-concept claims cautiously and validate behavior only in isolated lab environments against the vendor’s description.

Am I affected? How to find it in your systems

Microsoft Office is typically installed on Windows workstations, laptops, and some terminal servers or VDI images used for document editing. RTF parsing is a core feature of Word and related components, so any supported or legacy Office installation that still opens RTF files is in scope until the vendor update is confirmed applied.

If your inventory cannot confirm the exact patch level, assume the system remains vulnerable until verified against the vendor advisory.

How to remediate

Patch first. Apply the Microsoft security update that addresses CVE-2010-3333, following the vendor’s installation and reboot guidance. The CISA-required action is simply to apply updates per vendor instructions; do not rely on partial or third-party backports unless Microsoft explicitly supports them.

If you can't patch immediately

Implement compensating controls while you schedule the update:

These measures reduce likelihood and impact but do not eliminate the vulnerability; treat them as stop-gaps only.

If your data may have been exposed

Actively exploited document vulnerabilities frequently lead to endpoint compromise, credential theft, and follow-on data exposure. If you have evidence of exploitation or suspicious RTF-related activity, isolate affected hosts, preserve memory and disk images for forensics, reset credentials, and review egress logs for data exfiltration. You can also run a free exposure scan of your email addresses against known breach data sets to determine whether associated accounts already appear in public breach corpora, then prioritize password resets and multi-factor authentication accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Office
WeaknessCWE-119
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 24, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities