MS16-029: Security Update for Microsoft Office to Address Remote Code Execution (3141806)

High Nessus Plugin ID 89752


The remote Windows host is affected by multiple vulnerabilities.


The remote Windows host has a version of Microsoft Office, Office Compatibility Pack, Office Web Apps, Microsoft SharePoint, Microsoft Word, or Word Viewer installed that is affected by multiple vulnerabilities :

- Multiple remote code execution vulnerabilities exist in Microsoft Office software due to improper handling of objects in memory. An attacker can exploit these, by convincing a user to open a specially crafted file, to execute arbitrary code in the context of the current user. (CVE-2016-0021, CVE-2016-0134)

- A security feature bypass vulnerability exists in Microsoft Office software due to an improperly signed binary file. An attacker with write access to the target host can exploit this, by overwriting the file with a malicious binary with a similar configuration, to execute arbitrary code. (CVE-2016-0057).


Microsoft has released a set of patches for Office 2007, 2010, 2013, 2013 RT, and 2016; Microsoft InfoPath 2007, 2010 and 2013; Microsoft Word 2007, 2010, 2013, 2013 RT, and 2016; Word Viewer; SharePoint Server 2010 and 2013; Microsoft Office Compatibility Pack; and Office Web Apps 2010 and 2013.

See Also

Plugin Details

Severity: High

ID: 89752

File Name: smb_nt_ms16-029.nasl

Version: $Revision: 1.7 $

Type: local

Agent: windows

Published: 2016/03/08

Modified: 2017/07/12

Dependencies: 27524, 13855, 84669, 57033, 74250

Risk Information

Risk Factor: High


Base Score: 9.3

Temporal Score: 7.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:POC/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:microsoft:office, cpe:/a:microsoft:word, cpe:/a:microsoft:word_viewer, cpe:/a:microsoft:sharepoint_server, cpe:/a:microsoft:office_compatibility_pack, cpe:/a:microsoft:office_web_apps, cpe:/a:microsoft:infopath

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2016/03/08

Vulnerability Publication Date: 2016/03/08

Reference Information

CVE: CVE-2016-0021, CVE-2016-0057, CVE-2016-0134

BID: 84024, 84026, 84030

OSVDB: 135546, 135548, 135547

MSFT: MS16-029

MSKB: 2956063, 2956110, 3039746, 3114414, 3114426, 3114690, 3114812, 3114814, 3114821, 3114824, 3114833, 3114855, 3114866, 3114873, 3114878, 3114880, 3114900, 3114901

IAVA: 2016-A-0063