GDI+ Remote Code Execution Vulnerability for Microsoft Lync 2010 Attendee (Admin level install) (KB3188400)

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
40.834%

CVE Information

Patch Details

Patch associated with this vulnerability is supported by ManageEngine.

Patch ID
21634

Patch Description
Security Update for Microsoft Lync 2010 Attendee (Admin level install) (KB3188400)

References

http://technet.microsoft.com/security/bulletin/MS16-120
http://www.securityfocus.com/bid/93377
http://www.securityfocus.com/bid/93380
http://www.securityfocus.com/bid/93385
http://www.securityfocus.com/bid/93390
http://www.securityfocus.com/bid/93394
http://www.securityfocus.com/bid/93395
http://www.securityfocus.com/bid/93403
http://www.securitytracker.com/id/1036988
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2016-7182
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2016-3209
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2016-3262
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2016-3396
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2016-3263