Vulnerability record · CVE-2016-3316 · published 9 August 2016
CVE-2016-3316: Microsoft Word memory corruption allows remote code execution
Microsoft · Word
Microsoft Word 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac contain a memory corruption flaw (CWE-119) that is triggered when a crafted file is opened. Because the flaw corrupts memory in a way that can be steered to code execution, it is a serious client-side risk for any environment still running these Office versions.
Description
Microsoft Word 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to execute arbitrary code via a crafted file, aka "Microsoft Office Memory Corruption Vulnerability."
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with a high EPSS score and public exploit code, but exploitation requires user interaction and the affected products are older Office releases.
What it is
Microsoft Word 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac contain a memory corruption flaw (CWE-119) that is triggered when a crafted file is opened. Because the flaw corrupts memory in a way that can be steered to code execution, it is a serious client-side risk for any environment still running these Office versions.
Impact
An attacker who gets a victim to open a malicious document can execute arbitrary code in the context of the logged-on user, giving full control of confidentiality, integrity, and availability on that host.
Attack surface
The vector is local (AV:L) with user interaction required (UI:R) and no privileges required (PR:N), meaning the attacker must deliver a crafted file and convince the user to open it in Word. No authentication to a remote service is needed; the entry point is the document itself.
Exploitation
CVE-2016-3316 is not listed in CISA KEV, but EPSS is high at 0.47194 (98.8th percentile) and a public Exploit-DB entry (40238) exists, indicating exploit code is available.
What to do
- Apply the Microsoft MS16-099 security update for the affected Word 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac builds.
- Where patching is delayed, block or sandbox untrusted Office documents and disable macros and ActiveX content.
- Use Office Protected View and File Block settings to prevent documents from untrusted sources opening directly in Word.
- Run Office under a low-privilege account and consider application isolation or exploit mitigation (EMET/Windows Defender Exploit Guard) for legacy hosts.
- Retire or upgrade unsupported Word 2013/2016 builds that no longer receive security fixes.
Detection
- Monitor for WINWORD.EXE spawning child processes such as cmd.exe, powershell.exe, or wscript.exe, which is abnormal for document editing.
- Alert on Word processes making outbound network connections or writing executables to user-writable paths.
- Hunt for documents matching known exploit patterns or hashes associated with Exploit-DB 40238 and related Office memory corruption samples.
- Review endpoint telemetry for crashes in WINWORD.EXE followed by process creation, which can indicate exploitation attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-3316 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-3316), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.