cbcvebase.
CVE-2016-3313
published 2016-08-09

CVE-2016-3313: Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016, Word 2016 for Mac, and Word Viewer allow remote attackers to execute arbitrary code via a…

PriorityP262high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
49.83%
98.8th percentile
Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016, Word 2016 for Mac, and Word Viewer allow remote attackers to execute arbitrary code via a crafted file, aka "Microsoft Office Memory Corruption Vulnerability."

Affected

11 ranges
VendorProductVersion rangeFixed in
microsoftoffice
microsoftoffice
microsoftoffice
microsoftword_for_mac
msrcmicrosoft_office_2007_service_pack_3
msrcmicrosoft_office_2010_service_pack_2
msrcmicrosoft_office_2013_rt_service_pack_1
msrcmicrosoft_office_2013_service_pack_1
msrcmicrosoft_office_2016
msrcmicrosoft_office_word_viewer
msrcmicrosoft_word_2016_for_mac

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://smsecurity.net/wp-content/uploads/2016/08/COSIG-2016-31.doc
urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/40224.zip
filenameCOSIG-2016-31.doc
  • Detect opening of specially crafted .doc files with an invalid WordDocumentStream, which triggers an out-of-bounds read leading to code execution in Microsoft Word 2007/2010/2013/2016.
  • The Preview Pane is NOT an attack vector; detections should focus on file-open events rather than preview actions.
  • Monitor for Word process spawning unexpected child processes after opening a .doc file, consistent with arbitrary code execution in the context of the current user.
  • ·Exploit status at time of advisory was 'Publicly Disclosed: No; Exploited: No', but a public PoC (.doc file and zip archive) was released on 2016-08-09 alongside the patch, so in-the-wild exploitation risk should be reassessed.
  • ·Affected platforms include both Windows and macOS (Word 2016 for Mac), so detection and patching scope must cover both operating systems.

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.