CVE-2016-0126 is a memory corruption vulnerability in Microsoft Office 2013 SP1, 2013 RT SP1, and 2016 that allows remote attackers to execute arbitrary code through a crafted Office document. With a CVSS score of 7.8 (High), it presents a significant risk, requiring user interaction (UI:R) but with low attack complexity (AC:L) to achieve high confidentiality, integrity, and availability impacts (C:H/I:H/A:H). Despite its high severity and EPSS score, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. The vulnerability is categorized under CWE-119, indicating a memory corruption issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.