CVE-2016-0141: Microsoft Office
Medium severity, CVSS 6.5. EPSS: 4.9% chance of exploitation in the next 30 days.
The Visual Basic macros in Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016 export a certificate-store private key during a document-save operation, which allows attackers to obtain sensitive information via unspecified vectors, aka "Microsoft Information Disclosure Vulnerability."
Affected products
- Microsoft Office: version 2007 only; version 2010 only; version 2013 only; version 2016 only
Published 2016-09-14. Last modified 2026-06-17.