← back
CVE-2016-5228

CVE-2016-5228

28Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 15%
from disclosure to weapon120 days
Published on NVDJul 3
1st PoC+120d
exploitation probability
15%top 4% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Stack-based buffer overflow in the PlayMacro function in ObjectXMacro.ObjectXMacro in WdMacCtl.ocx in Micro Focus Rumba 9.x before 9.3 HF 11997 and 9.4.x before 9.4 HF 12815 allows remote attackers to execute arbitrary code via a long MacroName argument. NOTE: some references mention CVE-2016-5226 but that is not a correct ID for any Rumba vulnerability.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.