CVE-2016-3235 is a critical vulnerability affecting multiple versions of Microsoft Visio and Visio Viewer, where improper library loading allows local users to elevate privileges through a specially crafted application. With a CVSS score of 7.8 (HIGH), this vulnerability has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, with exploit code available in Metasploit, and has garnered significant community discussion, indicating its relevance and potential threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:visio:2007:sp3:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:visio:2010:sp2:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:visio:2013:sp1:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:visio:2016:*:*:*:*:*:*:* | ||
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:visio_viewer:2007:sp3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.