CVE-2016-3303
HIGHMicrosoft Windows and Office Products - Remote Code Execution via Crafted Embedded Font
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-3303. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit leverages a memory corruption vulnerability in GDI+ due to improper validation of bitmap headers in EMF files, leading to an out-of-bounds memory access. The PoC demonstrates a crash via a malformed EMR_PLGBLT record with crafted biWidth, biHeight, biPlanes, and biBitCount values.
Description
The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016, Lync 2013 SP1, Lync 2010, Lync 2010 Attendee, and Live Meeting 2007 Console allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Windows Graphics Component RCE Vulnerability," a different vulnerability than CVE-2016-3304.
Exploits (1)
This exploit leverages a memory corruption vulnerability in GDI+ due to improper validation of bitmap headers in EMF files, leading to an out-of-bounds memory access. The PoC demonstrates a crash via a malformed EMR_PLGBLT record with crafted biWidth, biHeight, biPlanes, and biBitCount values.
References (4)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H