CVE-2016-3235
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Microsoft Office OLE DLL Side Loading Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Microsoft Office OLE DLL Side Loading Vulnerability."
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 43% (אחוזון 100) נכון ל-24/7/2026
מוצרים מושפעים
microsoft: visio; microsoft: visio viewer
קישורים
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-… PatchVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-… PatchVendor Advisory
- https://www.securify.nl/advisory/SFY20150804/microsoft_visio_multiple_dll_side… ExploitThird Party Advisory
- https://www.securify.nl/advisory/SFY20150804/microsoft_visio_multiple_dll_side… ExploitThird Party Advisory
- http://packetstormsecurity.com/files/137490/Microsoft-Visio-DLL-Hijacking.html Third Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2016/Jun/32 Broken LinkMailing ListThird Party Advisory
- http://www.securityfocus.com/archive/1/538685/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1036093 Broken LinkThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/137490/Microsoft-Visio-DLL-Hijacking.html Third Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2016/Jun/32 Broken LinkMailing ListThird Party Advisory