CVE-2016-3235
KEV PoC massDLL Side-Loading RCE in Microsoft Office OLE
CISA: Microsoft Office OLE DLL Side Loading Vulnerability
CVE-2016-3235 is a DLL side-loading vulnerability in the Microsoft Office Object Linking & Embedding (OLE) dynamic link library, caused by improper input validation before libraries are loaded. An attacker triggers the flaw by getting a user to open a crafted document or file in an affected version of Microsoft Office, causing the OLE component to load an attacker-supplied DLL instead of the legitimate library. Successful exploitation yields remote code execution on the victim system in the context of the signed-in user, enabling malware installation, data theft, or lateral movement. Any organization or individual running the affected Microsoft Office builds is exposed, with risk concentrated on endpoints where users open untrusted or emailed documents. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), confirming exploitation in the wild; CISA notes ransomware use is unknown, no public PoC is known, and EPSS assigns a high 43.4% probability of exploitation within 30 days (99th percentile).
What to do: Apply Microsoft Office security updates across all endpoints per vendor instructions; the fix shipped in Microsoft's mid-2016 Office updates, so any Office instance not patched since then — especially legacy, offline, or long-lived systems — should be verified and updated. Because the flaw is confirmed exploited in the wild, prioritize endpoints that handle untrusted documents, consider inspecting or blocking Office files from untrusted sources, and audit for DLL side-loading artifacts via application and DLL-load event logs.
| Microsoft Office | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Microsoft Office OLE DLL Side Loading Vulnerability."
- Affected
- Microsoft Office
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- visio, visio viewer
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H