CVE-2016-7248
published 2016-11-10CVE-2016-7248: Microsoft Video Control in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers…
PriorityP349high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
21.84%
97.3th percentile
Microsoft Video Control in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute arbitrary code via a crafted file, aka "Microsoft Video Control Remote Code Execution Vulnerability."
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| msrc | windows_10_for_32-bit_systems | — | — |
| msrc | windows_10_for_x64-based_systems | — | — |
| msrc | windows_10_version_1511_for_32-bit_systems | — | — |
| msrc | windows_10_version_1511_for_x64-based_systems | — | — |
| msrc | windows_10_version_1607_for_32-bit_systems | — | — |
| msrc | windows_10_version_1607_for_x64-based_systems | — | — |
| msrc | windows_7_for_32-bit_systems_service_pack_1 | — | — |
| msrc | windows_7_for_x64-based_systems_service_pack_1 | — | — |
| msrc | windows_8.1_for_32-bit_systems | — | — |
| msrc | windows_8.1_for_x64-based_systems | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_vista_service_pack_2 | — | — |
| msrc | windows_vista_x64_edition_service_pack_2 | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Video Control Remote Code Execution Vulnerability
vendor_msrc·2016-11-08·CVSS 7.8
CVE-2016-7248 [HIGH] Microsoft Video Control Remote Code Execution Vulnerability
Microsoft Video Control Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when Microsoft Video Control fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
To exploit the vulnerability, an attacker would have to convince a user to open either a speciall
GHSA
GHSA-85pg-wqq9-fjpj: Microsoft Video Control in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8
ghsa_unreviewed·2022-05-14
CVE-2016-7248 [HIGH] CWE-284 GHSA-85pg-wqq9-fjpj: Microsoft Video Control in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8
Microsoft Video Control in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute arbitrary code via a crafted file, aka "Microsoft Video Control Remote Code Execution Vulnerability."
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - November 2016
blogs_talos·2016-11-08
Microsoft Patch Tuesday - November 2016
## Microsoft Patch Tuesday - November 2016
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. For a detailed explanaiton of each of the categories listed below, please go to https://technet.microsoft.com/en-us/security/gg309177.aspx .
This month's release is packed full of goodies, but you don't want to wait to review them over Thanksgiving dinner as there are 14 unique bulletins addressing multiple vulnerabilities.
Critical bulletins address vulnerabilities in (alphabetically):
Adobe Flash Player
Edge
Graphics Component
Internet Explorer
Video Control
Windows The remaining bulletins are rated Important or Moderate and address vulnerabilities in the following products (listed alphabetically):
B
Talos
Microsoft Patch Tuesday - November 2016
blogs_talos·2016-11-08
Microsoft Patch Tuesday - November 2016
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. For a detailed explanaiton of each of the categories listed below, please go to https://technet.microsoft.com/en-us/security/gg309177.aspx.
This month's release is packed full of goodies, but you don't want to wait to review them over Thanksgiving dinner as there are 14 unique bulletins addressing multiple vulnerabilities.
Critical bulletins address vulnerabilities in (alphabetically):
- Adobe Flash Player
- Edge
- Graphics Component
- Internet Explorer
- Video Control
- Windows
The remaining bulletins are rated Important or Moderate and address vulnerabilities in the following products (listed alphabetically):
- Boot Manager*
- Common Log File System
http://www.securityfocus.com/bid/94028http://www.securitytracker.com/id/1037242https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-131http://www.securityfocus.com/bid/94028http://www.securitytracker.com/id/1037242https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-131
2016-11-10
Published