CVE-2016-0021: Microsoft Infopath

High severity, CVSS 7.8. EPSS: 23.9% chance of exploitation in the next 30 days.

Microsoft InfoPath 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

Affected products

  • Microsoft Infopath: version 2007 only; version 2010 only; version 2013 only

Published 2016-03-09. Last modified 2026-06-17.