CVE-2016-3278 is a memory corruption vulnerability affecting Microsoft Outlook 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016, allowing remote code execution through specially crafted Office documents. With a CVSS v3 score of 7.8 (High), it requires user interaction (UI:R) to open a malicious document, but successful exploitation grants an attacker full control over the affected system (C:H/I:H/A:H). There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:outlook:2010:sp2:*:*:*:*:x64:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:outlook:2013:sp1:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:outlook:2016:*:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:outlook_rt:2013:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.