CVE-2016-0141

MEDIUM

Microsoft Office - Information Disclosure

Title source: rule

Description

The Visual Basic macros in Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016 export a certificate-store private key during a document-save operation, which allows attackers to obtain sensitive information via unspecified vectors, aka "Microsoft Information Disclosure Vulnerability."

Scores

CVSS v3 6.5
EPSS 0.0771
EPSS Percentile 91.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Classification

CWE
CWE-200
Status published

Affected Products (6)

microsoft/office
microsoft/office
microsoft/office
microsoft/office
microsoft/office
n/a/n/a

Timeline

Published Sep 14, 2016
Tracked Since Feb 18, 2026