VYPR
Low severity3.3NVD Advisory· Published Sep 14, 2016· Updated May 6, 2026

CVE-2016-0137

CVE-2016-0137

Description

The Click-to-Run (C2R) implementation in Microsoft Office 2013 SP1 and 2016 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "Microsoft APP-V ASLR Bypass."

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CVE-2016-0137 is a low-severity ASLR bypass in Microsoft Office 2013 SP1 and 2016 Click-to-Run that allows local users to weaken memory protections.

Vulnerability

The Click-to-Run (C2R) implementation in Microsoft Office 2013 SP1 and Microsoft Office 2016 fails to properly handle memory addresses, allowing a local attacker to bypass Address Space Layout Randomization (ASLR). The vulnerability resides in the C2R component and affects only these two Office versions. [1]

Exploitation

An attacker must have local access to the system and be able to execute a crafted application. The application exploits the flaw in C2R's memory address handling, enabling the attacker to predict memory locations that should be randomized by ASLR. No special privileges or user interaction beyond local execution are required. [1]

Impact

Successful exploitation degrades the effectiveness of ASLR, a key exploit mitigation. This information disclosure reduces the effort needed to exploit other vulnerabilities, potentially facilitating further attacks such as remote code execution. The attacker does not gain direct code execution or elevated privileges solely from this bypass. [1]

Mitigation

Microsoft released security update MS16-107 (KB3185852) on September 13, 2016, which addresses this issue. All affected users should install the update. No workarounds are documented. The vulnerability is not listed in the Known Exploited Vulnerabilities (KEV) catalog. [1]

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.