CVE-2016-3278: Microsoft Outlook
High severity, CVSS 7.8. EPSS: 20.4% chance of exploitation in the next 30 days.
Microsoft Outlook 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Affected products
- Microsoft Outlook: version 2010 only; version 2013 only; version 2016 only
- Microsoft Outlook Rt: version 2013 only
Published 2016-07-13. Last modified 2026-06-17.