CVE Tools

CVE-2016-3209

Exploitation likely. EPSS gives it a 54% chance of exploitation in the next 30 days. No fix published yet.

Published Updated Sources: CVE.org, NVD

What to do

No fixed build or workaround is published yet. Limit exposure and watch for a patch.

Steps

Written by AI from the record
  1. Check whether your business uses Windows 7 or Windows 10, and whether you rely on Office/Word Viewer, .NET Framework, Live Meeting/Lync/Skype for Business, or Silverlight.
  2. Identify where users open files from outside your company (email attachments, downloads, shared documents) and confirm you don’t routinely open untrusted documents with embedded fonts.
  3. Block or quarantine documents and files from unknown/untrusted sources (especially ones containing fonts) until you can apply vendor guidance.
  4. Confirm you are up to date with Microsoft security updates for the affected products, noting that no specific fixed version is identified in the provided information.
  5. Tell users to avoid opening unexpected attachments or content that prompts them to view documents/preview content from unknown sources.

What it is

From the CVE record

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; Live Meeting 2007 Console; .NET Framework 3.0 SP2, 3.5, 3.5.1, 4.5.2, and 4.6; and Silverlight 5 allows remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "True Type Font Parsing Information Disclosure Vulnerability."

In plain language

Written by AI from the record

This Windows-related flaw can reveal small amounts of secret computer memory when someone tricks you into opening a document with a bad font, so most small businesses should be careful with untrusted files but it’s not a common “instant” remote attack.

In Microsoft Windows GDI/GDI+ TrueType font parsing, a user-opening step can disclose memory contents (CWE-200) that can weaken defenses like ASLR; the issue affects multiple Microsoft components such as .NET Framework, Microsoft Office/Word Viewer, Skype for Business, Lync, Live Meeting, and Silverlight.

If you're affected

  • Sensitive memory information leak
  • Greater chance of follow-up attacks
  • Compromise from malicious documents

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS99th
CISA KEV

Not in the catalog. CISA has not confirmed exploitation.

Public exploits

No public exploit or proof of concept found in the sources we track.

EPSS

54% chance of exploitation activity in the next 30 days, which ranks it in the 99th percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Attention now

Rising.

Lifecycle

23 events over 3631 days, from the signal feeds we watch.

  1. EPSS band changemoderate → highepss band change
  2. EPSS band changehigh → moderateepss band change
  3. EPSS band changemoderate → highepss band change
  4. EPSS band changehigh → moderateepss band change
  5. EPSS band changemoderate → highepss band change
  6. EPSS band changehigh → moderate

Affected products

Technical detail

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Scored 5.5 by NVD.

How it is reached

  • Attack Vector LocalRequires local access to the vulnerable system (e.g. local login, malicious file)
  • Attack Complexity LowNo special conditions — the attack can be reliably reproduced
  • Privileges Required NoneNo authentication required — anyone can exploit this
  • User Interaction RequiredA user must click a link, open a file, or perform some action

Scope

  • Scope UnchangedImpact is limited to the vulnerable component itself

Impact if exploited

  • Confidentiality HighTotal information disclosure — all data in the component is compromised
  • Integrity NoneNo integrity impact
  • Availability NoneNo availability impact

Weaknesses

ATT&CK techniques

Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for .net Framework, not every advisory.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store