Junglewise Threat Intelligence

CVE-2016-3393: Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability

CVE-2016-3393 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-05-25

Technologies: Microsoft Windows 10, Microsoft Windows Server 2008, Microsoft Windows Vista, Microsoft Windows, Microsoft Windows 8.1, Microsoft Windows Server 2012, Microsoft Windows 7, Microsoft Windows Rt 8.1. Vendors: Microsoft.

Executive brief

A remote code execution vulnerability exists in the Windows Graphics Device Interface (GDI) component due to improper handling of objects in memory. An attacker could exploit this by convincing a user to visit a specially crafted website, potentially taking full control of the affected system.

Affected products

  • Microsoft Windows Vista SP2
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8.1
  • Microsoft Windows Server 2012 Gold, R2
  • Microsoft Windows RT 8.1
  • Microsoft Windows 10 Gold, 1511, 1607

Timeline

  • 2016-10-19: disclosed: Initial CVE analysis
  • 2016-10-12: patched: Microsoft released security bulletin MS16-120
  • 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-25: exploited: Confirmed as exploited in the wild per CISA KEV entry

Related threats