CVE-2016-3396

Description

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007 Console allows remote attackers to execute arbitrary code via a crafted embedded font, aka GDI+ Remote Code Execution Vulnerability.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
32.397

Associated Vulnerability

VulnerabilityOS Platform
GDI+ Information Disclosure Vulnerability for Windows 8.1 for x64-based Systems (KB3192392)Windows
GDI+ Information Disclosure Vulnerability for Windows 8.1 (KB3192392)Windows
GDI+ Information Disclosure Vulnerability for Windows Server 2012 R2 (KB3192392)Windows
GDI+ Information Disclosure Vulnerability for Windows Server 2012 R2 (KB3185331)Windows
GDI+ Information Disclosure Vulnerability for Windows 8.1 for x64-based Systems (KB3185331)Windows
GDI+ Information Disclosure Vulnerability for Windows 8.1 (KB3185331)Windows
GDI+ Information Disclosure Vulnerability for Windows Server 2012 (KB3192393)Windows
GDI+ Information Disclosure Vulnerability for Windows Server 2012 (KB3185332)Windows
GDI+ Information Disclosure Vulnerability for Windows 10 Version 1511 for x64-based Systems (KB3192441) - CumulativeWindows
GDI+ Information Disclosure Vulnerability for Windows 10 Version 1511 (KB3192441) - CumulativeWindows
GDI+ Information Disclosure Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB3194798) - CumulativeWindows
GDI+ Information Disclosure Vulnerability for Windows 10 Version 1607 (KB3194798) - CumulativeWindows
GDI+ Information Disclosure Vulnerability for Windows 10 for x64-based Systems (KB3192440) - CumulativeWindows
GDI+ Information Disclosure Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB3192391)Windows
GDI+ Information Disclosure Vulnerability for Windows 7 for x64-based Systems (KB3192391)Windows
GDI+ Information Disclosure Vulnerability for Windows 7 (KB3192391)Windows
GDI+ Information Disclosure Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB3185330)Windows
GDI+ Information Disclosure Vulnerability for Windows 7 for x64-based Systems (KB3185330)Windows
GDI+ Information Disclosure Vulnerability for Windows 7 (KB3185330)Windows
GDI+ Remote Code Execution Vulnerability for Windows Server 2008 x64 Edition (KB3191203)Windows
GDI+ Remote Code Execution Vulnerability for Windows Server 2008 (KB3191203)Windows
GDI+ Remote Code Execution Vulnerability for Windows Vista for x64-based Systems (KB3191203)Windows
GDI+ Remote Code Execution Vulnerability for Windows Vista (KB3191203)Windows
GDI+ Remote Code Execution Vulnerability for Microsoft Office 2010 (KB3118317) 64-Bit EditionWindows
GDI+ Remote Code Execution Vulnerability for Microsoft Office 2010 (KB3118317) 32-Bit EditionWindows
GDI+ Remote Code Execution Vulnerability for Word Viewer (KB3118394)Windows
GDI+ Remote Code Execution Vulnerability for Skype for Business 2016 (KB3118327) 64-Bit EditionWindows
GDI+ Remote Code Execution Vulnerability for Skype for Business 2016 (KB3118327) 32-Bit EditionWindows
GDI+ Remote Code Execution Vulnerability for Skype for Business 2015 (KB3118348) 64-Bit EditionWindows
GDI+ Remote Code Execution Vulnerability for Skype for Business 2015 (KB3118348) 32-Bit EditionWindows
GDI+ Remote Code Execution Vulnerability for Microsoft Lync 2010 Attendee (Admin level install) (KB3188400)Windows
GDI+ Remote Code Execution Vulnerability for Microsoft Lync 2010 (32 -bit) (KB3188397)Windows
GDI+ Remote Code Execution Vulnerability for Microsoft Lync 2010 (64 -bit) (KB3188397)Windows
GDI+ Remote Code Execution Vulnerability for Microsoft Office 2007 suites (KB3118301)Windows
GDI+ Remote Code Execution Vulnerability for Microsoft Silverlight (KB3193713)Windows
GDI+ Remote Code Execution Vulnerability for Microsoft Silverlight (KB3193713) x64 bases systemsWindows
GDI+ Remote Code Execution Vulnerability for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3188730) x64 bases systemsWindows
GDI+ Remote Code Execution Vulnerability for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3188730) x86 based systemsWindows
GDI+ Remote Code Execution Vulnerability for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3188732) x64 bases systemsWindows
GDI+ Remote Code Execution Vulnerability for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3188732)Windows
GDI+ Remote Code Execution Vulnerability for Microsoft .NET Framework 4.5.2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3189039) x64 bases systemsWindows
GDI+ Remote Code Execution Vulnerability for Microsoft .NET Framework 4.5.2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3189039) x86 based systemsWindows
GDI+ Remote Code Execution Vulnerability for Microsoft .NET Framework 4.6 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3189040) x64 bases systemsWindows
GDI+ Remote Code Execution Vulnerability for Microsoft .NET Framework 4.6 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3189040) x86 based systemsWindows
GDI+ Remote Code Execution Vulnerability for Microsoft .NET Framework 3.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3188726) x64 bases systemsWindows
GDI+ Remote Code Execution Vulnerability for Microsoft .NET Framework 3.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3188726) x86 based systemsWindows
GDI+ Remote Code Execution Vulnerability for Windows 10 (KB3192440)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-21582October, 2016 Security Only Quality Update for Windows 8.1 for x64-based Systems (KB3192392)
PATCH-21580October, 2016 Security Only Quality Update for Windows 8.1 (KB3192392)
PATCH-21589October, 2016 Security Only Quality Update for Windows Server 2012 R2 (KB3192392)
PATCH-21649October, 2016 Security Monthly Quality Rollup for Windows Server 2012 R2 (KB3185331)
PATCH-21648October, 2016 Security Monthly Quality Rollup for Windows 8.1 for x64-based Systems (KB3185331)
PATCH-21644October, 2016 Security Monthly Quality Rollup for Windows 8.1 (KB3185331)
PATCH-21588October, 2016 Security Only Quality Update for Windows Server 2012 (KB3192393)
PATCH-21647October, 2016 Security Monthly Quality Rollup for Windows Server 2012 (KB3185332)
PATCH-21535Cumulative Update for Windows 10 Version 1511 for x64-based Systems (KB3192441)
PATCH-21534Cumulative Update for Windows 10 Version 1511 (KB3192441)
PATCH-21537Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB3194798)
PATCH-21536Cumulative Update for Windows 10 Version 1607 (KB3194798)
PATCH-21533Cumulative Update for Windows 10 for x64-based Systems (KB3192440)
PATCH-21586October, 2016 Security Only Quality Update for Windows Server 2008 R2 for x64-based Systems (KB3192391)
PATCH-21585October, 2016 Security Only Quality Update for Windows 7 for x64-based Systems (KB3192391)
PATCH-21579October, 2016 Security Only Quality Update for Windows 7 (KB3192391)
PATCH-21646October, 2016 Security Monthly Quality Rollup for Windows Server 2008 R2 for x64-based Systems (KB3185330)
PATCH-21645October, 2016 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB3185330)
PATCH-21643October, 2016 Security Monthly Quality Rollup for Windows 7 (KB3185330)
PATCH-21583Security Update for Windows Server 2008 x64 Edition (KB3191203)
PATCH-21577Security Update for Windows Server 2008 (KB3191203)
PATCH-21581Security Update for Windows Vista for x64-based Systems (KB3191203)
PATCH-21575Security Update for Windows Vista (KB3191203)
PATCH-21619Security Update for Microsoft Office 2010 (KB3118317) 64-Bit Edition
PATCH-21618Security Update for Microsoft Office 2010 (KB3118317) 32-Bit Edition
PATCH-21629Security Update for Skype for Business 2016 (KB3118327) 64-Bit Edition
PATCH-21628Security Update for Skype for Business 2016 (KB3118327) 32-Bit Edition
PATCH-21631Security Update for Skype for Business 2015 (KB3118348) 64-Bit Edition
PATCH-21630Security Update for Skype for Business 2015 (KB3118348) 32-Bit Edition
PATCH-21634Security Update for Microsoft Lync 2010 Attendee (Admin level install) (KB3188400)
PATCH-21632Security Update for Microsoft Lync 2010 (32 -bit) (KB3188397)
PATCH-21633Security Update for Microsoft Lync 2010 (64 -bit) (KB3188397)
PATCH-21617Security Update for Microsoft Office 2007 suites (KB3118301)
PATCH-21614Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3188730)
PATCH-21555Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3188730)
PATCH-21616Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3188732)
PATCH-21552Security Update for Microsoft .NET Framework 4.5.2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3189039)
PATCH-21551Security Update for Microsoft .NET Framework 4.5.2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3189039)
PATCH-21532Cumulative Update for Windows 10 (KB3192440)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234