LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2016-7193: Microsoft Office Memory Corruption Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2016-7193 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Office contains a memory corruption vulnerability which can allow for remote code execution.

CVE-2016-7193 is a memory corruption vulnerability in Microsoft Office that can allow remote code execution. For IT and security teams, it matters because successful abuse of this class of flaw can let an attacker run code in the context of the user who opens a crafted Office file, potentially leading to further compromise of the endpoint or broader environment.

Public detail is limited to the vendor and CISA descriptions; confirm exact affected products, builds, and fixed updates against the Microsoft advisory before acting.

How it works

This issue is classified as CWE-119 (improper restriction of operations within the bounds of a memory buffer). In Microsoft Office, memory corruption flaws of this type typically arise when the application mishandles specially crafted document content, causing it to write or read outside the intended memory region.

An attacker abuses the weakness by delivering a malicious Office file (for example via email or a download) and tricking a user into opening it. If the vulnerable code path is reached, the corruption can be leveraged to achieve remote code execution under the privileges of the logged-on user. Specific exploit mechanics, trigger formats, and reliability are not detailed in the provided facts; treat any public proof-of-concept claims cautiously and validate against the vendor advisory.

Am I affected? How to find it in your systems

Microsoft Office is commonly installed on Windows endpoints used for productivity work—desktops, laptops, and sometimes terminal or VDI sessions. Inventory every system that has Office components present.

Confirm scope and detection guidance with the official vendor advisory, as public detail here is limited.

How to remediate

Patch first. Apply the security updates Microsoft released for this vulnerability, following the vendor instructions referenced by CISA (“Apply updates per vendor instructions”).

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These measures lower risk but do not replace the official patch.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities in desktop applications can lead to endpoint compromise and subsequent data theft or ransomware, although ransomware use is not documented for this specific CVE. If you suspect exploitation, isolate affected hosts, collect forensic images, rotate credentials that may have been accessible from the system, and follow your incident-response plan. You can also run a free exposure scan of your email addresses against known breach data to check whether credentials or personal information have appeared in prior breaches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Office
WeaknessCWE-119
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 24, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities