ZeroHour

CVE-2016-3235

KEV PoC mass

DLL Side-Loading RCE in Microsoft Office OLE

CISA: Microsoft Office OLE DLL Side Loading Vulnerability

CVSS 3.1
7.8 high
EPSS
43%p99
Published
()
KEV added
AI analysis

CVE-2016-3235 is a DLL side-loading vulnerability in the Microsoft Office Object Linking & Embedding (OLE) dynamic link library, caused by improper input validation before libraries are loaded. An attacker triggers the flaw by getting a user to open a crafted document or file in an affected version of Microsoft Office, causing the OLE component to load an attacker-supplied DLL instead of the legitimate library. Successful exploitation yields remote code execution on the victim system in the context of the signed-in user, enabling malware installation, data theft, or lateral movement. Any organization or individual running the affected Microsoft Office builds is exposed, with risk concentrated on endpoints where users open untrusted or emailed documents. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), confirming exploitation in the wild; CISA notes ransomware use is unknown, no public PoC is known, and EPSS assigns a high 43.4% probability of exploitation within 30 days (99th percentile).

What to do: Apply Microsoft Office security updates across all endpoints per vendor instructions; the fix shipped in Microsoft's mid-2016 Office updates, so any Office instance not patched since then — especially legacy, offline, or long-lived systems — should be verified and updated. Because the flaw is confirmed exploited in the wild, prioritize endpoints that handle untrusted documents, consider inspecting or blocking Office files from untrusted sources, and audit for DLL side-loading artifacts via application and DLL-load event logs.

Affected
Microsoft Office
Estimated exposure
mass≈ hundreds of millions of Office installations/users worldwide (Office is near-ubiquitous on Windows endpoints) — Microsoft Office is deployed on the large majority of corporate and consumer Windows endpoints globally, so the plausible affected population is in the hundreds of millions of users, though practical exploitability is limited to systems…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Microsoft Office OLE DLL Side Loading Vulnerability."

CISA Known Exploited Vulnerability
Affected
Microsoft Office
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
visio, visio viewer
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news