CVE-2016-3304
HIGHMicrosoft Windows and Office - Remote Code Execution via Crafted Embedded Font
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-3304. PoCs published by Google Security Research.
AI-analyzed exploit summary This is a detailed writeup describing a heap corruption vulnerability in Microsoft GDI+ due to improper validation of the 'offDx' field in EMF records, leading to out-of-bounds writes during text rendering. The analysis includes a crash log and exploitation steps but does not contain executable exploit code.
Description
The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016, Lync 2013 SP1, Lync 2010, Lync 2010 Attendee, and Live Meeting 2007 Console allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Windows Graphics Component RCE Vulnerability," a different vulnerability than CVE-2016-3303.
Exploits (1)
This is a detailed writeup describing a heap corruption vulnerability in Microsoft GDI+ due to improper validation of the 'offDx' field in EMF records, leading to out-of-bounds writes during text rendering. The analysis includes a crash log and exploitation steps but does not contain executable exploit code.
References (4)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H