cbcvebase.
CVE-2016-3357
published 2016-09-14

CVE-2016-3357: Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 2016 for Mac, Word Viewer, Word…

PriorityP266high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
54.81%
98.9th percentile
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 2016 for Mac, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, SharePoint Server 2013 SP1, Excel Automation Services on SharePoint Server 2013 SP1, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

Affected

10 ranges
VendorProductVersion rangeFixed in
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice_web_apps
microsoftoffice_web_apps_server
microsoftsharepoint_foundation
microsoftsharepoint_foundation
microsoftword_for_mac
microsoftword_for_mac

Detection & IOCsextracted from sources · hover to see the quote

filename3525170180.ppt
urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/40406.zip
snort
SIDs: 40082-40124
  • The vulnerability is triggered by opening a specially crafted MS Office file (e.g., .ppt); monitor for Office processes spawning unexpected child processes or crashing with invalid pointer dereferences in ppcore.dll.
  • Crash occurs in ppcore!DllGetLCID at offset +0x18205e due to ECX pointing to invalid memory; look for access violations in ppcore.dll during PowerPoint file parsing.
  • Suspect heap corruption in PowerPoint 2010 (ppcore.dll 14.0.7168.5000, mso.dll 14.0.7166.5000); memory write access at eax+0x10 is the key trigger point for the invalid pointer reference.
  • ·Snort SID ranges listed cover the entire MS16-107 bulletin (13 vulnerabilities); not all SIDs are exclusively for CVE-2016-3357. Verify specific SID-to-CVE mapping on Snort.org or FireSIGHT Defense Center.
  • ·The PoC crash exhibits different crashing contexts depending on breakpoint timing, suggesting a heap corruption bug that Application Verifier may not reliably detect.

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.