RULE(RULE ID:312617)

Rule General Information
Release Date: 2016-01-12
Rule Name: Microsoft Office ASLR Security Bypass Vulnerability (CVE-2016-0012)
Severity:
CVE ID:
Rule Protection Details
Description: Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Visio 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Visio 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Office 2016, Excel 2016, PowerPoint 2016, Visio 2016, Word 2016, and Visual Basic 6.0 Runtime allow remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "Microsoft Office ASLR Bypass."
Impact: ASLR is the abbreviation of address space layout randomization, it is a technology to prevent buffer overflow attempt. The ASLR technoloy in the affected product can be bypassed by an attacker, which may occur buffer overflow attacks or arbitrary code execution.
Affected OS: Windows
Reference: MicrosoftSecurityBulletin:MS16-004
SecurityTrackerID:1034651
Solutions
Microsoft has released a patch MS16-004 to eliminate the vulnerability. The patch can be downloaded at http://technet.microsoft.com/security/bulletin/MS16-004