CVE-2016-7257

Description

The GDI component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office for Mac 2011, and Office 2016 for Mac allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka GDI Information Disclosure Vulnerability.

Risk Information

Base Score
6.6
MODERATE
Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
13.293

Associated Vulnerability

VulnerabilityOS Platform
Microsft Browser Information Disclosure Vulnerability for Windows 10 for x64-based Systems (KB3205383) - CumulativeWindows
Microsft Browser Information Disclosure Vulnerability for Windows Server 2012 R2 (KB3205401)Windows
Microsft Browser Information Disclosure Vulnerability for Windows 8.1 for x64-based Systems (KB3205401)Windows
Microsft Browser Information Disclosure Vulnerability for Windows 8.1 (KB3205401)Windows
Microsft Browser Information Disclosure Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB3206632) - CumulativeWindows
Microsft Browser Information Disclosure Vulnerability for Windows 10 Version 1607 (KB3206632) - CumulativeWindows
Microsft Browser Information Disclosure Vulnerability for Windows 10 Version 1511 for x64-based Systems (KB3205386) - CumulativeWindows
Microsft Browser Information Disclosure Vulnerability for Windows 10 Version 1511 (KB3205386) - CumulativeWindows
Windows GDI Information Disclosure Vulnerability for Microsoft Office Word 2007 (KB3128025)Windows
Windows GDI Information Disclosure Vulnerability for Microsoft Word 2010 (KB3128034) 64-Bit EditionWindows
Windows GDI Information Disclosure Vulnerability for Microsoft Word 2010 (KB3128034) 32-Bit EditionWindows
Windows GDI Information Disclosure Vulnerability for Microsoft SharePoint Server 2010 (KB3128026)Windows
Windows GDI Information Disclosure Vulnerability for Microsoft Office Compatibility Pack Service Pack 3 (KB3128024)Windows
Windows GDI Information Disclosure Vulnerability for Microsoft Web Applications (KB3128035)Windows
Windows GDI Information Disclosure Vulnerability for Microsoft Office 2010 (KB3128032) 64-Bit EditionWindows
Windows GDI Information Disclosure Vulnerability for Microsoft Office 2010 (KB3128032) 32-Bit EditionWindows
Microsft Browser Information Disclosure Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB3205394)Windows
Microsft Browser Information Disclosure Vulnerability for Windows 7 for x64-based Systems (KB3205394)Windows
Microsft Browser Information Disclosure Vulnerability for Windows 7 (KB3205394)Windows
Microsft Browser Information Disclosure Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB3207752)Windows
Microsft Browser Information Disclosure Vulnerability for Windows 7 for x64-based Systems (KB3207752)Windows
Microsft Browser Information Disclosure Vulnerability for Windows 7 (KB3207752)Windows
Microsft Browser Information Disclosure Vulnerability for Windows Server 2012 R2 (KB3205400)Windows
Microsft Browser Information Disclosure Vulnerability for Windows 8.1 for x64-based Systems (KB3205400)Windows
Microsft Browser Information Disclosure Vulnerability for Windows 8.1 (KB3205400)Windows
Microsft Browser Information Disclosure Vulnerability for Windows Server 2012 (KB3205408)Windows
Windows GDI Information Disclosure Vulnerability for Microsoft Publisher 2010 (KB3114395) 64-Bit EditionWindows
Windows GDI Information Disclosure Vulnerability for Microsoft Publisher 2010 (KB3114395) 32-Bit EditionWindows
Windows GDI Information Disclosure Vulnerability for Microsoft Office Compatibility Pack Service Pack 3 (KB3128022)Windows
Windows GDI Information Disclosure Vulnerability for Microsoft Excel 2010 (KB3128037) 64-Bit EditionWindows
Windows GDI Information Disclosure Vulnerability for Microsoft Excel 2010 (KB3128037) 32-Bit EditionWindows
Windows GDI Information Disclosure Vulnerability for Microsoft Excel 2016 (KB3128016) 64-Bit EditionWindows
Windows GDI Information Disclosure Vulnerability for Microsoft Excel 2016 (KB3128016) 32-Bit EditionWindows
Windows GDI Information Disclosure Vulnerability for Microsoft Office Excel Viewer 2007 (KB3128023)Windows
Windows GDI Information Disclosure Vulnerability for Microsoft Excel 2013 (KB3128008) 64-Bit EditionWindows
Windows GDI Information Disclosure Vulnerability for Microsoft Excel 2013 (KB3128008) 32-Bit EditionWindows
Windows Graphics Component Remote Code Execution Vulnerability for Windows Server 2008 for x64-based Systems (KB3205638)Windows
Windows Graphics Component Remote Code Execution Vulnerability for Windows Server 2008 (KB3205638)Windows
Windows Graphics Component Remote Code Execution Vulnerability for Windows Vista for x64-based Systems (KB3205638)Windows
Windows Graphics Component Remote Code Execution Vulnerability for Windows Vista (KB3205638)Windows
Windows GDI Information Disclosure Vulnerability for Microsoft Office 2007 suites (KB2883033)Windows
Windows GDI Information Disclosure Vulnerability for Microsoft Office 2010 (KB2889841) 64-Bit EditionWindows
Windows GDI Information Disclosure Vulnerability for Microsoft Office 2010 (KB2889841) 32-Bit EditionWindows
Windows GDI Information Disclosure Vulnerability for Word Viewer (KB3127995)Windows
Windows GDI Information Disclosure Vulnerability for Microsoft Office 2013 (KB3127968) 64-Bit EditionWindows
Windows GDI Information Disclosure Vulnerability for Microsoft Office 2013 (KB3127968) 32-Bit EditionWindows
Windows GDI Information Disclosure Vulnerability for Microsoft Office 2016 (KB3127986) 64-Bit EditionWindows
Windows GDI Information Disclosure Vulnerability for Microsoft Office 2016 (KB3127986) 32-Bit EditionWindows
Windows GDI Information Disclosure Vulnerability for Microsoft Office 2010 (KB3118380) 64-Bit EditionWindows
Windows GDI Information Disclosure Vulnerability for Microsoft Office 2010 (KB3118380) 32-Bit EditionWindows
Windows GDI Information Disclosure Vulnerability for Microsoft Office 2007 suites (KB3128020)Windows
Windows GDI Information Disclosure Vulnerability for Word Viewer (KB3128043)Windows
Windows Graphics Component Remote Code Execution Vulnerability for Windows Server 2008 for x64-based Systems (KB3204724)Windows
Windows Graphics Component Remote Code Execution Vulnerability for Windows Server 2008 (KB3204724)Windows
Windows Graphics Component Remote Code Execution Vulnerability for Windows Vista for x64-based Systems (KB3204724)Windows
Windows Graphics Component Remote Code Execution Vulnerability for Windows Vista (KB3204724)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-21828Cumulative Update for Windows 10 for x64-based Systems (KB3205383)
PATCH-21851December, 2016 Security Monthly Quality Rollup for Windows Server 2012 R2 (KB3205401)
PATCH-21850December, 2016 Security Monthly Quality Rollup for Windows 8.1 for x64-based Systems (KB3205401)
PATCH-21849December, 2016 Security Monthly Quality Rollup for Windows 8.1 (KB3205401)
PATCH-21832Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB3206632)
PATCH-21831Cumulative Update for Windows 10 Version 1607 (KB3206632)
PATCH-21830Cumulative Update for Windows 10 Version 1511 for x64-based Systems (KB3205386)
PATCH-21829Cumulative Update for Windows 10 Version 1511 (KB3205386)
PATCH-21859Security Update for Microsoft Office Word 2007 (KB3128025)
PATCH-21864Security Update for Microsoft Word 2010 (KB3128034) 32-Bit Edition
PATCH-21880Security Update for Microsoft SharePoint Server 2010 (KB3128026)
PATCH-21871Security Update for Microsoft Office Compatibility Pack Service Pack 3 (KB3128024)
PATCH-21883Security Update for Microsoft Web Applications (KB3128035)
PATCH-21861Security Update for Microsoft Office 2010 (KB3128032) 64-Bit Edition
PATCH-21860Security Update for Microsoft Office 2010 (KB3128032) 32-Bit Edition
PATCH-21840December, 2016 Security Only Quality Update for Windows Server 2008 R2 for x64-based Systems (KB3205394)
PATCH-21839December, 2016 Security Only Quality Update for Windows 7 for x64-based Systems (KB3205394)
PATCH-21838December, 2016 Security Only Quality Update for Windows 7 (KB3205394)
PATCH-21843December, 2016 Security Monthly Quality Rollup for Windows Server 2008 R2 for x64-based Systems (KB3207752)
PATCH-21842December, 2016 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB3207752)
PATCH-21841December, 2016 Security Monthly Quality Rollup for Windows 7 (KB3207752)
PATCH-21848December, 2016 Security Only Quality Update for Windows Server 2012 R2 (KB3205400)
PATCH-21847December, 2016 Security Only Quality Update for Windows 8.1 for x64-based Systems (KB3205400)
PATCH-21846December, 2016 Security Only Quality Update for Windows 8.1 (KB3205400)
PATCH-21844December, 2016 Security Only Quality Update for Windows Server 2012 (KB3205408)
PATCH-21870Security Update for Microsoft Office Compatibility Pack Service Pack 3 (KB3128022)
PATCH-21863Security Update for Microsoft Excel 2010 (KB3128037) 64-Bit Edition
PATCH-21862Security Update for Microsoft Excel 2010 (KB3128037) 32-Bit Edition
PATCH-21869Security Update for Microsoft Excel 2016 (KB3128016) 64-Bit Edition
PATCH-21868Security Update for Microsoft Excel 2016 (KB3128016) 32-Bit Edition
PATCH-21872Security Update for Microsoft Office Excel Viewer 2007 (KB3128023)
PATCH-21867Security Update for Microsoft Excel 2013 (KB3128008) 64-Bit Edition
PATCH-21866Security Update for Microsoft Excel 2013 (KB3128008) 32-Bit Edition
PATCH-21963Security Update for Windows Server 2008 for x64-based Systems (KB3205638)
PATCH-21853Security Update for Windows Server 2008 (KB3205638)
PATCH-21962Security Update for Windows Vista for x64-based Systems (KB3205638)
PATCH-21852Security Update for Windows Vista (KB3205638)
PATCH-21875Security Update for Microsoft Office 2007 suites (KB2883033)
PATCH-21882Security Update for Microsoft Office 2010 (KB2889841) 64-Bit Edition
PATCH-21881Security Update for Microsoft Office 2010 (KB2889841) 32-Bit Edition
PATCH-21893Security Update for Word Viewer (KB3127995)
PATCH-21888Security Update for Microsoft Office 2013 (KB3127968) 64-Bit Edition
PATCH-21887Security Update for Microsoft Office 2013 (KB3127968) 32-Bit Edition
PATCH-21890Security Update for Microsoft Office 2016 (KB3127986) 64-Bit Edition
PATCH-21889Security Update for Microsoft Office 2016 (KB3127986) 32-Bit Edition
PATCH-21892Security Update for Word Viewer (KB3128043)
PATCH-21837Security Update for Windows Server 2008 for x64-based Systems (KB3204724)
PATCH-21835Security Update for Windows Server 2008 (KB3204724)
PATCH-21836Security Update for Windows Vista for x64-based Systems (KB3204724)
PATCH-21834Security Update for Windows Vista (KB3204724)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234