The host is installed with Microsoft Office 2007, 2010 or 2013 and is prone to a remote code execution vulnerability. A flaw is present in the applications, which fail to properly validate templates. An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the current user.