← Vulnerability feed

Vulnerability record · CVE-2016-3235 · published 16 June 2016

CVE-2016-3235: Microsoft Visio and Visio Viewer OLE DLL side-loading privilege escalation

Microsoft · Visio

Microsoft Visio 2007 SP3, 2010 SP2, 2013 SP1, 2016 and Visio Viewer 2007 SP3/2010 mishandle library loading, allowing a crafted application to load an attacker-controlled DLL. Because the flaw is in a widely deployed Office component and is listed in CISA KEV, it matters to any environment still running these versions.

7.8 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 43% · top 1.3%
7.8CVSS 3.1 base score, v2 9.3
43%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
13References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Microsoft Office OLE DLL Side Loading Vulnerability."

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCVSS 7.8, CISA KEV listing and a high EPSS percentile indicate active exploitation risk, though the attack requires local access and user interaction.

What it is

Microsoft Visio 2007 SP3, 2010 SP2, 2013 SP1, 2016 and Visio Viewer 2007 SP3/2010 mishandle library loading, allowing a crafted application to load an attacker-controlled DLL. Because the flaw is in a widely deployed Office component and is listed in CISA KEV, it matters to any environment still running these versions.

Impact

An attacker who can place a malicious DLL and get a user to open a crafted file or application gains code execution in the context of the victim, potentially escalating privileges on the local system.

Attack surface

Reached locally: the CVSS vector is AV:L with UI:R and PR:N, so the attacker needs local access or a way to plant a file and must rely on user interaction to trigger the load. No authentication is required.

Exploitation

CVE-2016-3235 is in CISA KEV (added 2021-11-03) and has an EPSS 30-day probability of 0.434 (98.7th percentile), and a reference is tagged Exploit, indicating public exploit material exists.

What to do

  • Apply the Microsoft MS16-070 update for all affected Visio and Visio Viewer versions.
  • Remove or upgrade unsupported Visio 2007/2010/2013 installations that cannot be patched.
  • Restrict write access to application and working directories so untrusted users cannot drop DLLs where Visio loads them.
  • Block untrusted Visio and OLE documents at email and web gateways, and disable OLE object activation where not needed.
  • Monitor KEV remediation deadlines and confirm patched status across endpoints.

Detection

  • Alert on Visio or Visio Viewer processes loading DLLs from user-writable paths such as Downloads, Temp or Desktop.
  • Hunt for unexpected DLL files written next to Visio executables or in the same directory as opened Visio documents.
  • Review process creation where visio.exe or the Visio Viewer spawns child processes such as cmd.exe or powershell.exe.
  • Correlate file-write events in user directories with subsequent Visio process starts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2016-3235 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Office OLE DLL Side Loading Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-3235 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2007-0671Microsoft Excel remote code execution via malformed fileCVE-2007-0671 is an unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, that allows re…KEVEPSS 43%analysed10.0CVE-2003-0347Microsoft VBA SDK VBE DLL heap buffer overflow via long ID parameterVBE.DLL and VBE6.DLL in the Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 contain a heap-based buffer overflow triggered by a doc…EPSS 55%analysed9.3CVE-2015-2503Microsoft access permissions and access controls vulnerabilityMicrosoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2007 SP3, Visio 2007…EPSS 17%9.3CVE-2015-2557Microsoft visio memory buffer overflow vulnerabilityBuffer overflow in Microsoft Visio 2007 SP3 and 2010 SP2 allows remote attackers to execute arbitrary code via crafted UML data in an Office document…EPSS 22%9.3CVE-2013-0079Microsoft office filter pack vulnerabilityMicrosoft Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file that triggers incorrect memory allocation,…EPSS 27%9.3CVE-2012-1888Microsoft visio memory buffer overflow vulnerabilityBuffer overflow in Microsoft Visio 2010 SP1 and Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file, aka…EPSS 24%9.3CVE-2012-0018Microsoft visio viewer improper input validation vulnerabilityMicrosoft Visio Viewer 2010 Gold and SP1 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary cod…EPSS 25%9.3CVE-2012-0019Microsoft visio viewer code injection vulnerabilityMicrosoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitr…EPSS 20%

Source: NIST National Vulnerability Database (record CVE-2016-3235), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.