cbcvebase.
CVE-2016-7182
published 2016-10-14

CVE-2016-7182: The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows…

PriorityP271critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
30.32%
98.0th percentile
The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007 Console allows attackers to execute arbitrary code via a crafted True Type font, aka "True Type Font Parsing Elevation of Privilege Vulnerability."

Affected

25 ranges
VendorProductVersion rangeFixed in
microsoftlive_meeting
microsoftlync
microsoftlync
microsoftoffice
microsoftoffice
microsoftskype_for_business
microsoftwindows_10
microsoftwindows_10
microsoftwindows_server_2008
microsoftwindows_server_2012
msrcmicrosoft_live_meeting_2007_console
msrcmicrosoft_lync_2010
msrcmicrosoft_lync_2010_attendee
msrcmicrosoft_lync_2013_service_pack_1
msrcmicrosoft_lync_basic_2013_service_pack_1
msrcmicrosoft_office_2007_service_pack_3
msrcmicrosoft_office_2010_service_pack_2
msrcmicrosoft_office_word_viewer
msrcskype
msrcwindows_10
msrcwindows_10_version_1511
msrcwindows_10_version_1607
msrcwindows_7
msrcwindows_8.1
msrcwindows_rt_8.1

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/40599.zip
  • Vulnerability is triggered via crafted TTF font files with malicious mutations in the 'OS/2' and 'VDMX' tables, causing use-after-free in win32k!sbit_Embolden and win32k!ttfdCloseFontContext
  • Crash manifests as NULL pointer dereference during list unlinking OR write to freed memory, both in win32k.sys during TTF font processing — monitor for kernel bugchecks 0x8E or 0xCC originating from win32k.sys with csrss.exe as the faulting process
  • Exploitation requires the 'Adjust for best performance' performance option to be set (disabling 'Smooth edges of screen fonts'); monitor for registry changes to this setting in conjunction with suspicious font loading activity
  • PoC requires a custom program that displays all font glyphs at various point sizes to trigger the vulnerability; suspicious applications enumerating all glyphs of a loaded font at multiple sizes should be investigated
  • ·Crash is easiest to reproduce with Special Pools enabled for win32k.sys; on default Windows installations the crash may be delayed or non-deterministic
  • ·The Office 2010 update for this CVE is NOT applicable on Windows Vista and later because the vulnerable code is not present in that configuration
  • ·Lync 2013 (Skype for Business) requires prerequisite updates 2965218 and 3039779 to be installed before the security update can be applied

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc9.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.