peter bassill · operator
$ cve CVE-2016-3235 JSON

CVE-2016-3235 KEV EXPLOIT

7.8
HIGH · CVSS 3.1 · EPSS 43.3% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Microsoft Office OLE DLL Side Loading Vulnerability."

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS43.31% — more likely to be exploited than 99% of all CVEs
On CISA KEVyes — remediate by 2022-05-03
Public exploityes
Published2016-06-16
Last modified2026-06-17

CISA KEV

NameMicrosoft Office OLE DLL Side Loading Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productMicrosoft / Office
Ransomware usenone reported

Affected (2)

VendorProduct
microsoftvisio
microsoftvisio viewer

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD