Executive brief
A remote code execution vulnerability exists in the Windows font library (atmfd.dll) when improperly handling specially crafted embedded Open Type fonts. An attacker could exploit this by hosting a malicious website, potentially gaining full control of the affected system.
Affected products
- Microsoft Windows Vista SP2
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1 Gold
- Microsoft Windows Server 2012 Gold, R2
- Microsoft Windows RT 8.1 Gold
- Microsoft Windows 10 Gold, 1511, 1607
- Microsoft Windows Server 2016 Gold
Timeline
- 2016-11-08: advisory: Microsoft Security Bulletin MS16-132 published.
- 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2022-05-25: disclosed: NVD publication date.