CVE-2016-0137
published 2016-09-14CVE-2016-0137: The Click-to-Run (C2R) implementation in Microsoft Office 2013 SP1 and 2016 allows local users to bypass the ASLR protection mechanism via a crafted…
PriorityP415low3.3CVSS 3.0
AVLACLPRNUIRSUCLINAN
EPSS
6.77%
93.2th percentile
The Click-to-Run (C2R) implementation in Microsoft Office 2013 SP1 and 2016 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "Microsoft APP-V ASLR Bypass."
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | office | — | — |
| microsoft | office | — | — |
| msrc | microsoft_office_2013_service_pack_1 | — | — |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_msrc3.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft APP-V Security Feature Bypass Vulnerability
vendor_msrc·2016-09-13·CVSS 3.3
CVE-2016-0137 [LOW] Microsoft APP-V Security Feature Bypass Vulnerability
Microsoft APP-V Security Feature Bypass Vulnerability
Description: An information disclosure vulnerability exists in the way that the Click-to-Run (C2R) components handle objects in memory, which could lead to an Address Space Layout Randomization (ASLR) bypass.
An attacker who successfully exploited the information disclosure vulnerability could use the obtained information to bypass the ASLR security mechanism in Windows, which helps protect users from a broad class of vulnerabilities. The ASLR bypass by itself does not allow arbitrary code execution; however, an attacker could use the ASLR bypass in conjunction with another vulnerability, such as a remote code execution vulnerability, that could leverage the ASLR bypass to run arbitrary code.
To exploit the ASLR bypass, an attacker wou
GHSA
GHSA-fpwc-2qp4-xhff: The Click-to-Run (C2R) implementation in Microsoft Office 2013 SP1 and 2016 allows local users to bypass the ASLR protection mechanism via a crafted a
ghsa_unreviewed·2022-05-14
CVE-2016-0137 [MEDIUM] GHSA-fpwc-2qp4-xhff: The Click-to-Run (C2R) implementation in Microsoft Office 2013 SP1 and 2016 allows local users to bypass the ASLR protection mechanism via a crafted a
The Click-to-Run (C2R) implementation in Microsoft Office 2013 SP1 and 2016 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "Microsoft APP-V ASLR Bypass."
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/92785http://www.securitytracker.com/id/1036785https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-107http://www.securityfocus.com/bid/92785http://www.securitytracker.com/id/1036785https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-107
2016-09-14
Published