Junglewise Threat Intelligence

CVE-2016-7256: Microsoft Windows Open Type Font Remote Code Execution Vulnerability

CVE-2016-7256 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-05-25

Technologies: Microsoft Windows 10, Microsoft Windows Server 2008, Microsoft Windows Vista, Microsoft Windows 8.1, Microsoft Windows Rt 8.1, Microsoft Windows, Microsoft Windows Server 2012, Microsoft Windows Server 2016, Microsoft Windows 7. Vendors: Microsoft.

Executive brief

A remote code execution vulnerability exists in the Windows font library (atmfd.dll) when improperly handling specially crafted embedded Open Type fonts. An attacker could exploit this by hosting a malicious website, potentially gaining full control of the affected system.

Affected products

  • Microsoft Windows Vista SP2
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8.1 Gold
  • Microsoft Windows Server 2012 Gold, R2
  • Microsoft Windows RT 8.1 Gold
  • Microsoft Windows 10 Gold, 1511, 1607
  • Microsoft Windows Server 2016 Gold

Timeline

  • 2016-11-08: advisory: Microsoft Security Bulletin MS16-132 published.
  • 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-05-25: disclosed: NVD publication date.

Related threats