cbcvebase.
CVE-2016-0010
published 2016-01-13

CVE-2016-0010: Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Excel for Mac 2011, PowerPoint for Mac 2011, Word for Mac 2011…

PriorityP351high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
21.61%
97.4th percentile
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Excel for Mac 2011, PowerPoint for Mac 2011, Word for Mac 2011, Excel 2016 for Mac, PowerPoint 2016 for Mac, Word 2016 for Mac, and Word Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

Affected

20 ranges
VendorProductVersion rangeFixed in
microsoftexcel_for_mac
microsoftexcel_for_mac
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice
microsoftpowerpoint_for_mac
microsoftpowerpoint_for_mac
microsoftword_for_mac
microsoftword_for_mac
msrcmicrosoft_excel_2016_for_mac
msrcmicrosoft_excel_for_mac_2011
msrcmicrosoft_office_2007_service_pack_3
msrcmicrosoft_office_2010_service_pack_2
msrcmicrosoft_office_2013_rt_service_pack_1
msrcmicrosoft_office_2013_service_pack_1
msrcmicrosoft_office_2016
msrcmicrosoft_office_word_viewer
msrcmicrosoft_word_2016_for_mac
msrcmicrosoft_word_for_mac_2011

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2016-0010 is a Microsoft Office RTF file handling heap overflow vulnerability; detection should focus on crafted RTF/Office documents triggering memory corruption in Office parsing components
  • Fortinet IPS signature referenced for a related Office/hlink memory corruption class; monitor for analogous Office RTF heap overflow signatures in IPS platforms
  • ·The provided sources do not contain a dedicated deep-dive article for CVE-2016-0010 itself; the Fortinet blog index references a 'Deep Analysis of CVE-2016-0010 - Microsoft Office RTF File Handling Heap Overflow Vulnerability' article but its content was not included in the supplied documents, so no file hashes, specific byte signatures, or PoC-derived IOCs for CVE-2016-0010 could be extracted

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.8CRITICAL
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.