peter bassill · operator
$ cve CVE-2016-5228 JSON

CVE-2016-5228 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 15.1% (pctl 97)

Patch early

A public exploit exists.

Description

Stack-based buffer overflow in the PlayMacro function in ObjectXMacro.ObjectXMacro in WdMacCtl.ocx in Micro Focus Rumba 9.x before 9.3 HF 11997 and 9.4.x before 9.4 HF 12815 allows remote attackers to execute arbitrary code via a long MacroName argument. NOTE: some references mention CVE-2016-5226 but that is not a correct ID for any Rumba vulnerability.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS15.12% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2016-07-03
Last modified2026-06-17

Affected (1)

VendorProduct
microfocusrumba

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD