CVE-2016-0141: Infoleak
The Visual Basic macros in Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016 export a certificate-store private key during a document-save operation, which allows attackers to obtain sensitive information via unspecified vectors, aka "Microsoft Information Disclosure Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0141?
CVE-2016-0141 has a severity rating of important according to Microsoft's security guidelines.
How do I fix CVE-2016-0141?
To remediate CVE-2016-0141, install the security update provided in Microsoft Knowledge Base Article MS16-107.
Which versions of Microsoft Office are affected by CVE-2016-0141?
CVE-2016-0141 affects Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016.
What type of vulnerability is CVE-2016-0141?
CVE-2016-0141 is classified as an information disclosure vulnerability due to the export of certificate-store private keys.
Can CVE-2016-0141 be exploited remotely?
CVE-2016-0141 requires local access to the affected system to exploit the vulnerability.