CVE-2012-0167: Microsoft Office

High severity, CVSS 9.3. EPSS: 29.2% chance of exploitation in the next 30 days.

Heap-based buffer overflow in the Office GDI+ library in Microsoft Office 2003 SP3 and 2007 SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted EMF image in an Office document, aka "GDI+ Heap Overflow Vulnerability."

Affected products

  • Microsoft Office: version 2003 only; version 2007 only

Published 2012-05-09. Last modified 2026-06-16.