Vulnerability record · CVE-2016-3235 · published 16 June 2016
CVE-2016-3235: Microsoft Visio and Visio Viewer OLE DLL side-loading privilege escalation
Microsoft · Visio
Microsoft Visio 2007 SP3, 2010 SP2, 2013 SP1, 2016 and Visio Viewer 2007 SP3/2010 mishandle library loading, allowing a crafted application to load an attacker-controlled DLL. Because the flaw is in a widely deployed Office component and is listed in CISA KEV, it matters to any environment still running these versions.
Description
Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Microsoft Office OLE DLL Side Loading Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8, CISA KEV listing and a high EPSS percentile indicate active exploitation risk, though the attack requires local access and user interaction.
What it is
Microsoft Visio 2007 SP3, 2010 SP2, 2013 SP1, 2016 and Visio Viewer 2007 SP3/2010 mishandle library loading, allowing a crafted application to load an attacker-controlled DLL. Because the flaw is in a widely deployed Office component and is listed in CISA KEV, it matters to any environment still running these versions.
Impact
An attacker who can place a malicious DLL and get a user to open a crafted file or application gains code execution in the context of the victim, potentially escalating privileges on the local system.
Attack surface
Reached locally: the CVSS vector is AV:L with UI:R and PR:N, so the attacker needs local access or a way to plant a file and must rely on user interaction to trigger the load. No authentication is required.
Exploitation
CVE-2016-3235 is in CISA KEV (added 2021-11-03) and has an EPSS 30-day probability of 0.434 (98.7th percentile), and a reference is tagged Exploit, indicating public exploit material exists.
What to do
- Apply the Microsoft MS16-070 update for all affected Visio and Visio Viewer versions.
- Remove or upgrade unsupported Visio 2007/2010/2013 installations that cannot be patched.
- Restrict write access to application and working directories so untrusted users cannot drop DLLs where Visio loads them.
- Block untrusted Visio and OLE documents at email and web gateways, and disable OLE object activation where not needed.
- Monitor KEV remediation deadlines and confirm patched status across endpoints.
Detection
- Alert on Visio or Visio Viewer processes loading DLLs from user-writable paths such as Downloads, Temp or Desktop.
- Hunt for unexpected DLL files written next to Visio executables or in the same directory as opened Visio documents.
- Review process creation where visio.exe or the Visio Viewer spawns child processes such as cmd.exe or powershell.exe.
- Correlate file-write events in user directories with subsequent Visio process starts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2016-3235 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Office OLE DLL Side Loading Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-3235 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-3235), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.