Junglewise Threat Intelligence

CVE-2016-3235: Microsoft Office OLE DLL Side Loading Vulnerability

CVE-2016-3235 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to improper input validation before loading libraries. This flaw allows local users to gain privileges or execute remote code via a crafted application or file.

Affected products

  • Microsoft Visio 2007 SP3
  • Microsoft Visio 2010 SP2
  • Microsoft Visio 2013 SP1
  • Microsoft Visio 2016
  • Microsoft Visio Viewer 2007 SP3
  • Microsoft Visio Viewer 2010

Timeline

  • 2016-06-14: patched: Microsoft released security bulletin MS16-070 to address this vulnerability.
  • 2021-11-03: kev added: CISA added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog.
  • 2021-11-03: disclosed: NVD publication date.
  • 2021-11-03: exploited: Vulnerability confirmed as exploited in the wild per CISA KEV catalog.

Related threats