Microsoft Office 2016 Click-to-Run allows a remote code execution vulnerability due to how objects are handled in memory, aka "Office Remote Code Execution Vulnerability"
No PoCs from references.
- https://github.com/ARPSyndicate/cve-scores