Skip to content
COOEY

EXPOSURES › CVE-2016-3235

CVE-2016-3235

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2016-3235 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 rceexploited-in-wildunpatched

Microsoft Office OLE DLL side loading vulnerability allowed remote code execution by improperly validating input before loading libraries.

This vulnerability in Microsoft Office's OLE DLL allowed attackers to execute arbitrary code remotely by exploiting improper input validation during library loading. DIB organizations must ensure Office is patched and configured to block DLL side loading to prevent compromise via malicious documents. The failure is avoidable through timely patching and proper security configurations.

Shame score — A known vulnerability in a widely deployed product that enabled remote code execution, representing a significant avoidable risk for unpatched systems.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to it improperly validating input before loading libraries. Successful exploitation allows for remote code execution.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Critical OLE DLL side-loading flaw in Office allowed remote code execution; NVD/NIST classify as severe, though vendor response is standard for the era.
cooey ↗ severe-fallout -0.80
NVD/NIST classify as critical remote code execution flaw; no praise for vendor handling.
"Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to it improperly validating input before loading libraries. Successful exploitation allows for remote code execution."
learn.microsoft.com ↗ severe-fallout -0.50
Vendor acknowledges critical severity but source text lacks explicit praise or condemnation.
"This security update resolves vulnerabilities in Microsoft Office. The most severe of the vulnerabilities could allow remote code execution if a user opens a specially crafted Microsoft Office file."
www.cnbc.com ↗ severe-fallout -0.40
CNBC reports on a later SharePoint attack, implying lingering vulnerability concerns.
"Microsoft hit with SharePoint attack — one version still vulnerable"
NVD ↗ severe-fallout +0.00
NVD vulnerabilities page provides no vendor-specific sentiment.
NIST ↗ severe-fallout +0.00
NIST NVD page provides no vendor-specific sentiment.
www.microsoft.com ↗ severe-fallout +0.00
Microsoft Exploitability Index page provides no vendor-specific sentiment.
NVD ↗ severe-fallout +0.00
NVD home page provides no vendor-specific sentiment.
AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized