CVE-2016-3281 is a memory corruption vulnerability affecting multiple versions of Microsoft Office, Word, Office Web Apps, and SharePoint Server. It allows remote attackers to execute arbitrary code through a crafted Office document. Rated with a CVSS score of 7.8 (High), this vulnerability requires user interaction (UI:R) and local access (AV:L) but can lead to complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). While no public exploit code is readily available (Metasploit, Nuclei, ExploitDB), its high EPSS score and FAUCET Risk Score of 97/100 indicate a significant potential for exploitation, despite limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office_web_apps:2010:sp2:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2010:sp2:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:word:2013:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.