Vulnerability Name: CVE-2016-3357 (CCN-116425) Assigned: 2016-09-13 Published: 2016-09-13 Updated: 2018-10-30 Summary: Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 2016 for Mac, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, SharePoint Server 2013 SP1, Excel Automation Services on SharePoint Server 2013 SP1, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." CVSS v3 Severity: 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H )7.0 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): RequiredScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
8.4 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H )7.6 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
CVSS v2 Severity: 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
Vulnerability Type: CWE-119 Vulnerability Consequences: Gain Access References: Source: MITRE Type: CNACVE-2016-3357 Source: CCN Type: Microsoft Security Bulletin MS16-107Security Update for Office (3185852) Source: CCN Type: Microsoft Security Bulletin MS16-121Security Update for Microsoft Office (3194063) Source: CCN Type: Microsoft Security Bulletin MS16-133Security Update for Microsoft Office (3199168) Source: CCN Type: Microsoft Security Bulletin MS16-148Security Update for Microsoft Office (3204068) Source: CCN Type: Microsoft Security Bulletin MS17-002Security Update for Microsoft Office (3214291) Source: CCN Type: Microsoft Security Bulletin MS17-013Security Update for Microsoft Graphics Component (4013075) Source: CCN Type: Microsoft Security Bulletin MS17-014Security Update for Microsoft Office (4013241) Source: BID Type: UNKNOWN92786 Source: SECTRACK Type: UNKNOWN1036785 Source: MS Type: UNKNOWNMS16-107 Source: XF Type: UNKNOWNms-office-cve20163357-code-exec(116425) Source: CCN Type: Packet Storm Security [09-21-2016]Microsoft Office PowerPoint 2010 Invalid Pointer Reference Source: EXPLOIT-DB Type: EXPLOITOffensive Security Exploit Database [09-21-2016] Source: EXPLOIT-DB Type: UNKNOWN40406 Vulnerable Configuration: Configuration 1 :cpe:/a:microsoft:office:2007:sp3:*:*:*:*:*:* OR cpe:/a:microsoft:office:2010:sp2:*:*:*:*:*:* OR cpe:/a:microsoft:office:2013:sp1:*:*:*:*:*:* OR cpe:/a:microsoft:office:2016:*:*:*:*:*:*:* OR cpe:/a:microsoft:office_web_apps:2010:sp2:*:*:*:*:*:* OR cpe:/a:microsoft:office_web_apps_server:2013:sp1:*:*:*:*:*:* OR cpe:/a:microsoft:sharepoint_foundation:2010:sp2:*:*:*:*:*:* OR cpe:/a:microsoft:sharepoint_foundation:2013:sp1:*:*:*:*:*:* OR cpe:/a:microsoft:word_for_mac:2011:*:*:*:*:*:*:* OR cpe:/a:microsoft:word_for_mac:2016:*:*:*:*:*:*:* OR cpe:/a:microsoft:word_viewer:*:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:microsoft:word_viewer:*:*:*:*:*:*:*:* OR cpe:/a:microsoft:office:2007:sp3:*:*:*:*:*:* OR cpe:/a:microsoft:office:2010:sp2:*:*:*:*:x64:* OR cpe:/a:microsoft:office:2010:sp2:x32:*:*:*:*:* OR cpe:/a:microsoft:office_web_apps:2010:sp2:*:*:*:*:*:* OR cpe:/a:microsoft:office_web_apps:2013:sp1:*:*:*:*:*:* OR cpe:/a:microsoft:office:2013:sp1:x32:*:*:*:*:* OR cpe:/a:microsoft:office:2013:sp1:*:*:*:*:x64:* OR cpe:/a:microsoft:office:2013:sp1:*:*:rt:*:*:* OR cpe:/a:microsoft:sharepoint_server:2013:sp1:*:*:*:*:*:* OR cpe:/a:microsoft:word:2011:*:*:*:mac:*:*:* OR cpe:/a:microsoft:office:2016:*:x32:*:*:*:*:* OR cpe:/a:microsoft:office:2016:*:*:*:*:*:x64:* AND cpe:/a:microsoft:sharepoint_server:2010:sp2:*:*:*:*:*:* Denotes that component is vulnerable BACK
microsoft office 2007 sp3
microsoft office 2010 sp2
microsoft office 2013 sp1
microsoft office 2016
microsoft office web apps 2010 sp2
microsoft office web apps server 2013 sp1
microsoft sharepoint foundation 2010 sp2
microsoft sharepoint foundation 2013 sp1
microsoft word for mac 2011
microsoft word for mac 2016
microsoft word viewer *
microsoft word viewer *
microsoft office 2007 sp3
microsoft office 2010 sp2
microsoft office 2010 sp2
microsoft office web apps 2010 sp2
microsoft office web apps 2013 sp1
microsoft office 2013 sp1
microsoft office 2013 sp1
microsoft office 2013 sp1
microsoft sharepoint server 2013 sp1
microsoft word 2011
microsoft office 2016
microsoft office 2016
microsoft sharepoint server 2010 sp2