CVE-2018-1016: Input Validation
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-1010, CVE-2018-1012, CVE-2018-1013, CVE-2018-1015.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1016?
CVE-2018-1016 has a critical severity rating due to the potential for remote code execution.
How do I fix CVE-2018-1016?
To fix CVE-2018-1016, install the latest security updates provided by Microsoft for the affected versions of Windows.
Which versions of Windows are affected by CVE-2018-1016?
CVE-2018-1016 affects several versions including Windows 7, Windows 8.1, and multiple editions of Windows Server.
What type of vulnerability is CVE-2018-1016?
CVE-2018-1016 is classified as a remote code execution vulnerability.
Can CVE-2018-1016 be exploited remotely?
Yes, CVE-2018-1016 can be exploited remotely through specially crafted embedded fonts.