CVE-2016-0057
published 2016-03-09CVE-2016-0057: Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016 does not properly sign an unspecified binary file, which allows local users to gain privileges via a…
PriorityP336high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
1.49%
71.3th percentile
Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016 does not properly sign an unspecified binary file, which allows local users to gain privileges via a Trojan horse file with a crafted signature, aka "Microsoft Office Security Feature Bypass Vulnerability."
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - March 2016
blogs_talos·2016-03-08·CVSS 6.5
[MEDIUM] Microsoft Patch Tuesday - March 2016
## Microsoft Patch Tuesday - March 2016
Patch Tuesday for March 2016 has arrived. Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release contains 13 bulletins addressing 44 vulnerabilities. Five bulletins are rated critical and address vulnerabilities in Edge, Graphic Fonts, Internet Explorer, Windows Media Player, and Window PDF. The remaining eight bulletins are rated important and address vulnerabilities in .NET, Office, and several other Windows components.
## Bulletins Rated Critical Microsoft bulletins MS16-023, MS16-024, MS16-026 through MS16-028, and MS16-036 are rated as critical in this month's release.
MS16-023 and MS16-024 are this month's Internet Explorer and Edge securi
Talos
Microsoft Patch Tuesday - March 2016
blogs_talos·2016-03-08·CVSS 6.5
[MEDIUM] Microsoft Patch Tuesday - March 2016
Patch Tuesday for March 2016 has arrived. Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release contains 13 bulletins addressing 44 vulnerabilities. Five bulletins are rated critical and address vulnerabilities in Edge, Graphic Fonts, Internet Explorer, Windows Media Player, and Window PDF. The remaining eight bulletins are rated important and address vulnerabilities in .NET, Office, and several other Windows components.
### Bulletins Rated Critical Microsoft bulletins MS16-023, MS16-024, MS16-026 through MS16-028, and MS16-036 are rated as critical in this month's release.
MS16-023 and MS16-024 are this month's Internet Explorer and Edge security bulletin respectively. In total, 24 v
Bugzilla
CVE-2016-1522 graphite2: Null pointer dereference and out-of-bounds access vulnerabilities
bugzilla·2016-02-09·CVSS 8.8
CVE-2016-1522 [HIGH] CVE-2016-1522 graphite2: Null pointer dereference and out-of-bounds access vulnerabilities
CVE-2016-1522 graphite2: Null pointer dereference and out-of-bounds access vulnerabilities
Exploitable NULL pointer dereference and out-of-bound access vulnerabilities were found in the bidirectional font handling functionality of Libgraphite. A specially crafted font can cause out-of-bound access resulting into remote code execution and NULL pointer dereference resulting into crash. An attacker can provide a malicious font to trigger this vulnerability.
External References:
http://www.talosintel.com/reports/TALOS-2016-0060/
http://www.talosintel.com/reports/TALOS-2016-0057/
Discussion:
Created graphite2 tracking bugs for this issue:
Affects: fedora-all [bug 1305811]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
http://www.securityfocus.com/bid/84030http://www.securitytracker.com/id/1035207https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-029http://www.securityfocus.com/bid/84030http://www.securitytracker.com/id/1035207https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-029
2016-03-09
Published