← Back to CVE List
Vulnerability Intelligence Report

CVE-2016-7182

The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007 Console allows attackers to execute arbitrary code via a crafted True Type font, aka "True Type Font Parsing Elevation of Privilege Vulnerability."

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:30.32%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
microsoft live_meeting 2007
microsoft lync 2010, 2013
microsoft office 2007, 2010
microsoft skype_for_business 2016
microsoft word_viewer all
microsoft windows_10 1511, 1607
microsoft windows_7 all
microsoft windows_8.1 all
microsoft windows_rt_8.1 all
microsoft windows_server_2008 r2
microsoft windows_server_2012 r2
microsoft windows_vista all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
30.323%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMicrosoft Corporation · Vendor · USA
Reserved2016-09-09T00:00:00
Published2016-10-14T01:00:00
Patch Date2016-10-11
Last Updated2024-08-06T01:50:47

LINK COPIED TO CLIPBOARD