CVE-2022-41107
About
Microsoft Office Graphics Remote Code Execution Vulnerability
Rainforest analyst review
A remote-code-execution flaw in Microsoft Office's graphics handling: a maliciously crafted file, once opened, can run code in the context of the user. The vector is local with required user interaction, which in Office-speak means the classic path, a document arrives, someone opens it, and the graphics parser is the trigger. No privileges are needed on the attacker's side beyond getting the file in front of a victim.
This is phishing-shaped, and Office file RCE is a perennial favorite of both commodity crews and targeted actors because the delivery, an email with an attachment, is so well understood. The gate is genuine, the user has to open the document, but attacker tradecraft around exactly that has been refined for decades, so the interaction requirement slows exploitation without preventing it. Weaponized documents for a bug like this can circulate quietly.
Our focus is patch coverage across the Office and Microsoft 365 Apps estate, since these ship on nearly every endpoint, plus the layered controls that catch the delivery: attachment filtering, Protected View, and endpoint detection watching for Office spawning child processes. We would rank it a solid priority in the monthly cycle, not a drop-everything emergency, because the user-interaction step gives our other defenses a place to intervene.
References
Related CVEs
No related CVEs.
Frequently asked questions
What is CVE-2022-41107?
Microsoft Office Graphics Remote Code Execution Vulnerability
How severe is CVE-2022-41107?
CVE-2022-41107 carries a CVSS 3.1 base score of 7.8, rated high. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 72 out of 100, in the high band.
How is CVE-2022-41107 exploited?
According to the CVSS vector (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H): attack vector Local, attack complexity Low, privileges required None, user interaction Required. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2022-41107?
Public advisories list the following as affected: 365 apps, office, office long term servicing channel. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2022-41107?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
