Lucene search

K
cveMicrosoftCVE-2016-3235
HistoryJun 16, 2016 - 1:59 a.m.

CVE-2016-3235

2016-06-1601:59:36
microsoft
web.nvd.nist.gov
887
In Wild
microsoft
visio
cve-2016-3235
vulnerability
security
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7

Confidence

High

EPSS

0.013

Percentile

86.0%

Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which allows local users to gain privileges via a crafted application, aka “Microsoft Office OLE DLL Side Loading Vulnerability.”

Affected configurations

Nvd
Node
microsoftvisioMatch2007sp3
OR
microsoftvisioMatch2010sp2
OR
microsoftvisioMatch2013sp1
OR
microsoftvisioMatch2016
OR
microsoftvisio_viewerMatch2007sp3
OR
microsoftvisio_viewerMatch2010
VendorProductVersionCPE
microsoftvisio2007cpe:2.3:a:microsoft:visio:2007:sp3:*:*:*:*:*:*
microsoftvisio2010cpe:2.3:a:microsoft:visio:2010:sp2:*:*:*:*:*:*
microsoftvisio2013cpe:2.3:a:microsoft:visio:2013:sp1:*:*:*:*:*:*
microsoftvisio2016cpe:2.3:a:microsoft:visio:2016:*:*:*:*:*:*:*
microsoftvisio_viewer2007cpe:2.3:a:microsoft:visio_viewer:2007:sp3:*:*:*:*:*:*
microsoftvisio_viewer2010cpe:2.3:a:microsoft:visio_viewer:2010:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7

Confidence

High

EPSS

0.013

Percentile

86.0%