First published: Tue Dec 20 2016(Updated: )
The GDI component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office for Mac 2011, and Office 2016 for Mac allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI Information Disclosure Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office for Mac OS X | =2011 | |
Microsoft Office for Mac OS X | =2016 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Vista | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7257 is classified as a moderate severity vulnerability that can lead to information disclosure.
To fix CVE-2016-7257, ensure that you have installed the latest security updates provided by Microsoft for the affected software.
CVE-2016-7257 affects Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Office for Mac 2011, and Office 2016 for Mac.
CVE-2016-7257 is an information disclosure vulnerability related to the GDI component of Microsoft software.
Yes, CVE-2016-7257 can be exploited remotely via a crafted web site to gain access to sensitive information from process memory.