CVE-2016-0145
published 2016-04-12CVE-2016-0145: The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT…
PriorityP273high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
43.27%
98.6th percentile
The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold and 1511; Office 2007 SP3 and 2010 SP2; Word Viewer; .NET Framework 3.0 SP2, 3.5, and 3.5.1; Skype for Business 2016; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; and Live Meeting 2007 Console allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Graphics Memory Corruption Vulnerability."
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | live_meeting | — | — |
| microsoft | lync | — | — |
| microsoft | lync | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | skype_for_business | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2012 | — | — |
| msrc | microsoft_live_meeting_2007_console | — | — |
| msrc | microsoft_lync_2010 | — | — |
| msrc | microsoft_lync_2010_attendee | — | — |
| msrc | microsoft_lync_2013_service_pack_1 | — | — |
| msrc | microsoft_lync_basic_2013_service_pack_1 | — | — |
| msrc | microsoft_net_framework_3.0_service_pack_2 | — | — |
| msrc | microsoft_net_framework_3.5 | — | — |
| msrc | microsoft_net_framework_3.5.1 | — | — |
| msrc | microsoft_office_2007_service_pack_3 | — | — |
| msrc | microsoft_office_2010_service_pack_2 | — | — |
| msrc | microsoft_office_word_viewer | — | — |
| msrc | microsoft_word_2007_service_pack_3 | — | — |
| msrc | microsoft_word_2010_service_pack_2 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect crafted TTF font files with malformed EBLC or EBSC tables; these tables are the offending mutation vector for CVE-2016-0145 pool corruption. ↗
- →The crash/exploit can be triggered by opening a malicious TTF file in the default Windows Font Viewer utility (fontview.exe); monitor for fontview.exe opening untrusted font files. ↗
- →Exploit delivery vectors include malicious websites with embedded fonts and malicious Office documents; monitor for Office processes or browsers spawning win32k font-processing activity with external/untrusted font files. ↗
- →The Preview Pane is an attack vector for this vulnerability on systems where severity is Critical; consider alerting on Preview Pane rendering of documents containing embedded fonts. ↗
- ·The pool corruption bugcheck (and thus the exploit) only reliably triggers when the 'Smooth edges of screen fonts' Visual Effects option is DISABLED in system settings. Default installations may not crash in win32k.sys directly but can still exhibit corruption elsewhere in kernel space. ↗
- ·The Office 2010 update for this CVE is not applicable on Windows Vista and later because the vulnerable code is not present in that configuration. ↗
- ·Customers running affected editions of Microsoft Lync 2013 (Skype for Business) must first install prerequisite updates (KB2965218 and KB3039779) before the security update will apply correctly. ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc8.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4crq-7m6j-8297: The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8
ghsa_unreviewed·2022-05-14
CVE-2016-0145 [HIGH] CWE-119 GHSA-4crq-7m6j-8297: The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8
The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold and 1511; Office 2007 SP3 and 2010 SP2; Word Viewer; .NET Framework 3.0 SP2, 3.5, and 3.5.1; Skype for Business 2016; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; and Live Meeting 2007 Console allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Graphics Memory Corruption Vulnerability."
Microsoft
GDI+ Remote Code Execution Vulnerability
vendor_msrc·2016-04-12·CVSS 8.8
CVE-2016-0145 [HIGH] GDI+ Remote Code Execution Vulnerability
GDI+ Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
There are multiple ways an attacker could exploit the vulnerability:
In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability and then convince users to view the website. A
No detection rules found.
Talos
Microsoft Patch Tuesday - April 2016
blogs_talos·2016-04-12·CVSS 8.8
[HIGH] Microsoft Patch Tuesday - April 2016
## Microsoft Patch Tuesday - April 2016
Bulletins MS16-037 through MS16-040 and bulletins MS16-042, MS16-050 are rated as critical in this month's release.
MS16-037 is related to six vulnerabilities in Internet Explorer. The most severe vulnerabilities allow an attacker to craft a website that executes arbitrary code on the victim's device due to the memory corruption vulnerabilities in the browser. The attacker would be limited to executing code with same administrative rights as the current user, but with many users having full administrator rights, an attacker could use this to take full control of a device. To exploit the vulnerability the attacker must get the victim to view attacker controlled content. Previously, this has not proved a major limitation for attackers. Attackers have
Talos
Microsoft Patch Tuesday - April 2016
blogs_talos·2016-04-12·CVSS 8.8
[HIGH] Microsoft Patch Tuesday - April 2016
Bulletins MS16-037 through MS16-040 and bulletins MS16-042, MS16-050 are rated as critical in this month's release.
MS16-037 is related to six vulnerabilities in Internet Explorer. The most severe vulnerabilities allow an attacker to craft a website that executes arbitrary code on the victim's device due to the memory corruption vulnerabilities in the browser. The attacker would be limited to executing code with same administrative rights as the current user, but with many users having full administrator rights, an attacker could use this to take full control of a device. To exploit the vulnerability the attacker must get the victim to view attacker controlled content. Previously, this has not proved a major limitation for attackers. Attackers have proved adept at sending spam messages, c
http://www.securitytracker.com/id/1035528http://www.securitytracker.com/id/1035529http://www.securitytracker.com/id/1035530http://www.securitytracker.com/id/1035531http://www.securitytracker.com/id/1035532https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-039https://www.exploit-db.com/exploits/39743/http://www.securitytracker.com/id/1035528http://www.securitytracker.com/id/1035529http://www.securitytracker.com/id/1035530http://www.securitytracker.com/id/1035531http://www.securitytracker.com/id/1035532https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-039https://www.exploit-db.com/exploits/39743/
2016-04-12
Published