CVE-2016-7256
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA.
Apply updates per vendor instructions.
A vulnerability in Windows font handling allows attackers to run malicious code on your computer by tricking you into visiting a specially crafted website. The flaw is in how Windows processes certain font files.
The atmfd.dll font library in affected Windows versions fails to properly validate OpenType font structures, allowing remote code execution through a web vector. An attacker crafts a malicious font file embedded in a website; when a victim visits the site, the font processing triggers memory corruption leading to arbitrary code execution with the privileges of the affected process.
The full analysis of this CVE is available in Portuguese →