CVE-2016-3235CISA KEV
Microsoft Office OLE DLL Side Loading Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to it improperly validating input before loading libraries. Successful exploitation allows for remote code execution.
- Product
- Office
- Added to KEV
- 3 Nov 2021
- Federal remediation due
- 3 May 2022
- Known ransomware use
- Not reported