CVE-2016-7256 — Microsoft Windows Open Type Font Remote Code Execution Vulnerability
CVE-2016-7256: Microsoft Windows Open Type Font Remote Code Execution Vulnerability
CISA Known Exploited Vulnerability (KEV)
| Vendor / project | Microsoft |
| Product | Windows |
| Date added | 2022-05-25 |
| Due date | 2022-06-15 |
| Ransomware campaign use | Unknown |
Description
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerability could take control of the affected system.
Required action (CISA)
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2016-7256
References
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2016-7256
- KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog