EXPOSURES › CVE-2016-3235
CVE-2016-3235
HIGH ⌖ ON CISA KEV · EXPLOITEDMicrosoft Office OLE DLL side loading vulnerability allowed remote code execution by improperly validating input before loading libraries.
This vulnerability in Microsoft Office's OLE DLL allowed attackers to execute arbitrary code remotely by exploiting improper input validation during library loading. DIB organizations must ensure Office is patched and configured to block DLL side loading to prevent compromise via malicious documents. The failure is avoidable through timely patching and proper security configurations.
Shame score — A known vulnerability in a widely deployed product that enabled remote code execution, representing a significant avoidable risk for unpatched systems.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to it improperly validating input before loading libraries. Successful exploitation allows for remote code execution.
"Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to it improperly validating input before loading libraries. Successful exploitation allows for remote code execution."
"This security update resolves vulnerabilities in Microsoft Office. The most severe of the vulnerabilities could allow remote code execution if a user opens a specially crafted Microsoft Office file."
"Microsoft hit with SharePoint attack — one version still vulnerable"
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |