CVE-2016-7256highunder attack

CVE-2016-7256

Published · Updated

63Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA.

ssvc Actcvss 8.8epss 65%
from disclosure to weapon
Published on NVDNov 10
CISA KEV+2022d
exploitation probability
65%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2022-06-15

Apply updates per vendor instructions.

In short

A vulnerability in Windows font handling allows attackers to run malicious code on your computer by tricking you into visiting a specially crafted website. The flaw is in how Windows processes certain font files.

Technical detail

The atmfd.dll font library in affected Windows versions fails to properly validate OpenType font structures, allowing remote code execution through a web vector. An attacker crafts a malicious font file embedded in a website; when a victim visits the site, the font processing triggers memory corruption leading to arbitrary code execution with the privileges of the affected process.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Open Type Font Remote Code Execution Vulnerability."
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
n/a · n/a