CVE-2016-3356

Description

The Graphics Device Interface (GDI) in Microsoft Windows 10 1607 allows remote attackers to execute arbitrary code via a crafted document, aka GDI Remote Code Execution Vulnerability.

Risk Information

Base Score
6.6
MODERATE
Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:P/RL:W/RC:C
EPSS Score
Exploitation Probability
20.505

Associated Vulnerability

VulnerabilityOS Platform
Windows Information Disclosure Vulnerability for Windows 10 for x64-based Systems (KB3185611) - CumulativeWindows
Windows Information Disclosure Vulnerability for Windows 10 Version 1511 for x64-based Systems (KB3185614) - CumulativeWindows
Windows Information Disclosure Vulnerability for Windows 10 Version 1511 (KB3185614) - CumulativeWindows
Win32k Elevation of Privilege Vulnerability for Windows Server 2008 x64 Edition (KB3185911)Windows
Win32k Elevation of Privilege Vulnerability for Windows Server 2008 (KB3185911)Windows
Win32k Elevation of Privilege Vulnerability for Windows Server 2008 x64 Edition (KB3185911)Windows
Win32k Elevation of Privilege Vulnerability for Windows Vista (KB3185911)Windows
Win32k Elevation of Privilege Vulnerability for Windows Server 2008 R2 x64 Edition (KB3185911)Windows
Win32k Elevation of Privilege Vulnerability for Windows 7 for x64-based Systems (KB3185911)Windows
Win32k Elevation of Privilege Vulnerability for Windows 7 (KB3185911)Windows
Win32k Elevation of Privilege Vulnerability for Windows Server 2012 (KB3185911)Windows
Win32k Elevation of Privilege Vulnerability for Windows Server 2012 R2 (KB3185911)Windows
Win32k Elevation of Privilege Vulnerability for Windows 8.1 for x64-based Systems (KB3185911)Windows
Win32k Elevation of Privilege Vulnerability for Windows 8.1 (KB3185911)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-21344Cumulative Update for Windows 10 for x64-based Systems (KB3185611)
PATCH-21346Cumulative Update for Windows 10 Version 1511 for x64-based Systems (KB3185614)
PATCH-21345Cumulative Update for Windows 10 Version 1511 (KB3185614)
PATCH-21354Security Update for Windows Server 2008 x64 Edition (KB3185911)
PATCH-21350Security Update for Windows Server 2008 (KB3185911)
PATCH-21353Security Update for Windows Server 2008 x64 Edition (KB3185911)
PATCH-21349Security Update for Windows Vista (KB3185911)
PATCH-21356Security Update for Windows Server 2008 R2 x64 Edition (KB3185911)
PATCH-21355Security Update for Windows 7 for x64-based Systems (KB3185911)
PATCH-21351Security Update for Windows 7 (KB3185911)
PATCH-21358Security Update for Windows Server 2012 (KB3185911)
PATCH-21359Security Update for Windows Server 2012 R2 (KB3185911)
PATCH-21357Security Update for Windows 8.1 for x64-based Systems (KB3185911)
PATCH-21352Security Update for Windows 8.1 (KB3185911)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234