CVE-2016-0170: Critical severity windows 10 vulnerability
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted document, aka "Windows Graphics Component RCE Vulnerability."
Affected Software
Event History
Frequently Asked Questions
Which Windows systems are in scope?
Systems running the listed Windows releases are affected: Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold or 1511, Windows Server 2008 SP2 or R2 SP1, and Windows Server 2012 Gold or R2.
What does an attacker need to exploit this vulnerability?
An attacker can exploit the issue remotely by supplying a crafted document. No attacker privileges are required, but the CVSS vector indicates user interaction is required, meaning a user must interact with the malicious document.
What is the potential impact of successful exploitation?
The vulnerability can result in arbitrary code execution, with high impact to confidentiality, integrity, and availability according to the supplied CVSS vector.