cbcvebase.
CVE-2016-0145
published 2016-04-12

CVE-2016-0145: The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT…

PriorityP273high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
43.27%
98.6th percentile
The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold and 1511; Office 2007 SP3 and 2010 SP2; Word Viewer; .NET Framework 3.0 SP2, 3.5, and 3.5.1; Skype for Business 2016; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; and Live Meeting 2007 Console allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Graphics Memory Corruption Vulnerability."

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftlive_meeting
microsoftlync
microsoftlync
microsoftnet_framework
microsoftnet_framework
microsoftnet_framework
microsoftoffice
microsoftoffice
microsoftskype_for_business
microsoftwindows_10
microsoftwindows_server_2008
microsoftwindows_server_2012
msrcmicrosoft_live_meeting_2007_console
msrcmicrosoft_lync_2010
msrcmicrosoft_lync_2010_attendee
msrcmicrosoft_lync_2013_service_pack_1
msrcmicrosoft_lync_basic_2013_service_pack_1
msrcmicrosoft_net_framework_3.0_service_pack_2
msrcmicrosoft_net_framework_3.5
msrcmicrosoft_net_framework_3.5.1
msrcmicrosoft_office_2007_service_pack_3
msrcmicrosoft_office_2010_service_pack_2
msrcmicrosoft_office_word_viewer
msrcmicrosoft_word_2007_service_pack_3
msrcmicrosoft_word_2010_service_pack_2

Detection & IOCsextracted from sources · hover to see the quote

filenamewin32k.sys
processcsrss.exe
  • Detect crafted TTF font files with malformed EBLC or EBSC tables; these tables are the offending mutation vector for CVE-2016-0145 pool corruption.
  • The crash/exploit can be triggered by opening a malicious TTF file in the default Windows Font Viewer utility (fontview.exe); monitor for fontview.exe opening untrusted font files.
  • Exploit delivery vectors include malicious websites with embedded fonts and malicious Office documents; monitor for Office processes or browsers spawning win32k font-processing activity with external/untrusted font files.
  • The Preview Pane is an attack vector for this vulnerability on systems where severity is Critical; consider alerting on Preview Pane rendering of documents containing embedded fonts.
  • ·The pool corruption bugcheck (and thus the exploit) only reliably triggers when the 'Smooth edges of screen fonts' Visual Effects option is DISABLED in system settings. Default installations may not crash in win32k.sys directly but can still exhibit corruption elsewhere in kernel space.
  • ·The Office 2010 update for this CVE is not applicable on Windows Vista and later because the vulnerable code is not present in that configuration.
  • ·Customers running affected editions of Microsoft Lync 2013 (Skype for Business) must first install prerequisite updates (KB2965218 and KB3039779) before the security update will apply correctly.

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc8.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.