CVE-2016-3301
published 2016-08-09CVE-2016-3301: The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2…
PriorityP266high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
44.49%
98.6th percentile
The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007 Console allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Windows Graphics Component RCE Vulnerability."
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | live_meeting | — | — |
| microsoft | lync | — | — |
| microsoft | lync | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | skype_for_business | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2012 | — | — |
| msrc | microsoft_live_meeting_2007_console | — | — |
| msrc | microsoft_lync_2010 | — | — |
| msrc | microsoft_lync_2010_attendee | — | — |
| msrc | microsoft_lync_2013_service_pack_1 | — | — |
| msrc | microsoft_lync_basic_2013_service_pack_1 | — | — |
| msrc | microsoft_office_2007_service_pack_3 | — | — |
| msrc | microsoft_office_2010_service_pack_2 | — | — |
| msrc | microsoft_office_word_viewer | — | — |
| msrc | skype | — | — |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1511 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_7 | — | — |
| msrc | windows_8.1 | — | — |
| msrc | windows_rt_8.1 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
pathC:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_5c02a2f5a011f9be\GdiPlus.dll↗
- →Look for EMF files embedding bitmaps with anomalous BITMAPINFOHEADER values: biWidth=0x05900000, biHeight=0x00000017, biPlanes=0x0001, biBitCount=0x0008, which produce a bytes_per_row of 0x590000 and output buffer size of 0x7ff00000, characteristic of the BI_RLE8 integer overflow exploit. ↗
- →Monitor for EMF records (EMR_PLGBLT, EMR_BITBLT, EMR_STRETCHBLT, EMR_STRETCHDIBITS) embedding BI_RLE8-compressed bitmaps with extremely large biWidth values that could trigger pointer arithmetic overflow in gdiplus!DecodeCompressedRLEBitmap on 32-bit Large Address Aware processes. ↗
- →Flag calls to GdipConvertToEmfPlus / GpMetafile::ConvertToEmfPlus processing untrusted EMF files in 32-bit /LARGEADDRESSAWARE processes, as this is the code path leading to the vulnerable DecodeCompressedRLEBitmap execution. ↗
- ·The crash/exploit is highly dependent on the process address space layout at the time the image is loaded; the provided poc.emf may not reliably crash GDI+ clients other than the specific test program built with /LARGEADDRESSAWARE. ↗
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6669-2rgv-wqcp: The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8
ghsa_unreviewed·2022-05-14
CVE-2016-3301 [HIGH] CWE-20 GHSA-6669-2rgv-wqcp: The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8
The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007 Console allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Windows Graphics Component RCE Vulnerability."
Microsoft
Microsoft Graphics Remote Code Execution Vulnerability
vendor_msrc·2016-08-09·CVSS 8.8
CVE-2016-3301 [HIGH] Microsoft Graphics Remote Code Execution Vulnerability
Microsoft Graphics Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
There are multiple ways an attacker could exploit the vulnerability:
In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability and then convince users to view
No detection rules found.
Talos
Microsoft Patch Tuesday - August 2016
blogs_talos·2016-08-09·CVSS 7.8
[HIGH] Microsoft Patch Tuesday - August 2016
This post was authored by Edmund Brumaghin and Jonah Samost
Today is Patch Tuesday for August 2016, and Microsoft has released several security bulletins and associated patches to resolve security issues across their products. This month’s patch release includes 9 bulletins addressing 28 vulnerabilities. Five of the bulletins Microsoft has released are rated Critical and address vulnerabilities in Internet Explorer, Edge, Windows Graphics Component, Microsoft Office, and the Windows PDF library. The remaining four bulletins are rated Important and address vulnerabilities in Windows Kernel-Mode Drivers, Secure Boot, Windows Authentication Methods, and ActiveSyncProvider.
## Bulletins Rated CriticalMicrosoft has listed bulletins MS16-095, MS16-096, MS16-097, MS16-099, MS16-102 as critical
Talos
Microsoft Patch Tuesday - August 2016
blogs_talos·2016-08-09·CVSS 7.8
[HIGH] Microsoft Patch Tuesday - August 2016
## Microsoft Patch Tuesday - August 2016
This post was authored by Edmund Brumaghin and Jonah Samost
Today is Patch Tuesday for August 2016, and Microsoft has released several security bulletins and associated patches to resolve security issues across their products. This month’s patch release includes 9 bulletins addressing 28 vulnerabilities. Five of the bulletins Microsoft has released are rated Critical and address vulnerabilities in Internet Explorer, Edge, Windows Graphics Component, Microsoft Office, and the Windows PDF library. The remaining four bulletins are rated Important and address vulnerabilities in Windows Kernel-Mode Drivers, Secure Boot, Windows Authentication Methods, and ActiveSyncProvider.
## Bulletins Rated Critical Microsoft has listed bulletins MS16-095, MS16-096
http://www.securityfocus.com/bid/92288http://www.securitytracker.com/id/1036564https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-097https://www.exploit-db.com/exploits/40255/http://www.securityfocus.com/bid/92288http://www.securitytracker.com/id/1036564https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-097https://www.exploit-db.com/exploits/40255/
2016-08-09
Published