CVE-2016-3360: Microsoft Office Compatibility Pack

High severity, CVSS 7.8. EPSS: 17.2% chance of exploitation in the next 30 days.

Microsoft PowerPoint 2007 SP3, PowerPoint 2010 SP2, PowerPoint 2013 SP1, PowerPoint 2013 RT SP1, PowerPoint 2016 for Mac, Office Compatibility Pack SP3, PowerPoint Viewer, SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

Affected products

  • Microsoft Office Compatibility Pack: any version
  • Microsoft Office Web Apps: version 2010 only
  • Microsoft Office Web Apps Server: version 2013 only
  • Microsoft PowerPoint: version 2007 only; version 2010 only; version 2013 only
  • Microsoft PowerPoint For Mac: version 2016 only
  • Microsoft PowerPoint Viewer: any version
  • Microsoft SharePoint Designer: version 2013 only

Published 2016-09-14. Last modified 2026-06-17.