LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2016-3235: Microsoft Office OLE DLL Side Loading Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2016-3235 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to it improperly validating input before loading libraries. Successful…

CVE-2016-3235 is a side-loading vulnerability in Microsoft Office’s Object Linking and Embedding (OLE) component. It arises because the OLE dynamic link library does not properly validate input before loading libraries, which can let an attacker achieve remote code execution. For IT and security teams this matters because Office is widely deployed on endpoints that handle untrusted documents; a successful exploit can give an attacker code execution in the context of the user who opens a crafted file.

Public detail is limited to the CISA description and the CWE classification. Confirm exact affected builds, patch identifiers, and any configuration prerequisites directly against the Microsoft vendor advisory before acting.

How it works

The weakness is classified as CWE-264 (permissions, privileges, and access controls). In this case the OLE DLL fails to validate input adequately before deciding which libraries to load. An attacker who can supply a malicious document or other OLE-related input can cause the application to load an unintended library from a location under the attacker’s control—a classic DLL side-loading pattern.

Once the rogue library is loaded, code executes with the privileges of the Office process. No further exploit mechanics, proof-of-concept details, or specific trigger conditions are provided in the available facts; treat any such claims as unverified until confirmed in the vendor advisory or trusted analysis.

Am I affected? How to find it in your systems

Microsoft Office is typically installed on Windows workstations, laptops, and some terminal servers used for document processing. Inventory every endpoint and virtual desktop that has any Office application capable of handling OLE objects.

How to remediate

Patch first. Apply the updates Microsoft released for this vulnerability exactly as instructed in the vendor advisory. CISA’s required action is simply to apply those updates per vendor instructions.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities in desktop applications frequently lead to follow-on compromise and data theft. Known ransomware use of this specific CVE is not documented, but that does not rule out other malicious activity. If you suspect exploitation, isolate affected hosts, preserve forensic evidence, and begin incident-response procedures. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Office
WeaknessCWE-264
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities