9.3
CVSSv2

CVE-2016-3357

Published: 14/09/2016 Updated: 30/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 2016 for Mac, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, SharePoint Server 2013 SP1, Excel Automation Services on SharePoint Server 2013 SP1, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote malicious users to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft word for mac 2011

microsoft word for mac 2016

microsoft sharepoint foundation 2010

microsoft sharepoint foundation 2013

microsoft office 2016

microsoft word viewer

microsoft office 2007

microsoft office web apps 2010

microsoft office web apps server 2013

microsoft office 2010

microsoft office 2013

Exploits

Source: bugschromiumorg/p/project-zero/issues/detail?id=866 The following crash was observed in Microsoft PowerPoint 2010 running under Windows 7 x86 with application verifier enabled File versions are: msodll: 14071665000 ppcoredll: 14071685000 Attached crashing file: 3525170180ppt Crashing context: eax=1979aea0 ebx=1 ...