CVE-2022-21842HighCVSS 7.8

Microsoft Word Remote Code Execution Vulnerability

Published
January 11, 2022
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector.

There are multiple update packages available for some of the affected software. Do I need to install all the updates listed in the Security Updates table for the software? Yes. Customers should apply all updates offered for the software installed on their systems. If multiple updates apply, they can be installed in any order.

🎯 Affected products3

  • Microsoft SharePoint Enterprise Server 2016
  • Microsoft Word 2016 (32-bit edition)
  • Microsoft Word 2016 (64-bit edition)

✅ Remediation

KB5002113 (Security Update) — fixed build 16.0.5266.1000 KB5002118 (Security Update) — fixed build 16.0.5266.1000 KB5002057 (Security Update) — fixed build 16.0.5266.1000

🔗 References (8)