cbcvebase.
CVE-2016-0012
published 2016-01-13

CVE-2016-0012: Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Visio 2010…

PriorityP427medium4.3CVSS 3.0
AVNACLPRNUIRSUCLINAN
EPSS
11.20%
95.5th percentile
Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Visio 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Visio 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Office 2016, Excel 2016, PowerPoint 2016, Visio 2016, Word 2016, and Visual Basic 6.0 Runtime allow remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "Microsoft Office ASLR Bypass."

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftexcel
microsoftexcel
microsoftexcel
microsoftexcel
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice
microsoftpowerpoint
microsoftpowerpoint
microsoftpowerpoint
microsoftvisio
microsoftvisio
microsoftvisio
microsoftvisio
microsoftvisual_basics
microsoftword
microsoftword
microsoftword
microsoftword
msrcmicrosoft_access_2016
msrcmicrosoft_excel_2003_service_pack_3
msrcmicrosoft_excel_2007_service_pack_3
msrcmicrosoft_excel_2010_service_pack_1
msrcmicrosoft_excel_2010_service_pack_2

CVSS provenance

nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_msrc4.3HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.