CVE-2016-0195: Buffer Overflow
The Imaging Component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted document, aka "Windows Imaging Component Memory Corruption Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this vulnerability?
An attacker can exploit this remotely without authentication, but exploitation requires a user to interact with a crafted document. Successful exploitation can result in arbitrary code execution with high impact to confidentiality, integrity, and availability.
Which systems are affected?
The affected releases listed are Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold and 1511. The issue is in the Windows Imaging Component.