Back

CVE-2016-7277

CRITICAL

Microsoft Office 2016 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

Published: Dec 20, 2016 Modified: Jun 17, 2026
CWE-119

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: REQUIRED Scope: CHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
microsoft office 2016

GitHub Security Advisory GHSA-6f9h-5q62-2mmx

Microsoft Office 2016 allows remote attackers to execute arbitrary code or cause a denial of...

Risk Scores

CVSS Score 9.6 / 10
EPSS Score 17.97%

Top 3% most likely to be exploited

Threat Score 43.8 / 100

Data Sources

NVD EPSS GitHub