CVE-2016-3209

Published on: 10/13/2016 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:02 PM UTC

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Certain versions of .net Framework from Microsoft contain the following vulnerability:

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; Live Meeting 2007 Console; .NET Framework 3.0 SP2, 3.5, 3.5.1, 4.5.2, and 4.6; and Silverlight 5 allows remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "True Type Font Parsing Information Disclosure Vulnerability."

  • CVE-2016-3209 has been assigned by [email protected] to track the vulnerability - currently rated as MEDIUM severity.

CVSS3 Score: 5.5 - MEDIUM

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
LOCAL LOW NONE REQUIRED
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED HIGH NONE NONE

CVSS2 Score: 5 - MEDIUM

Access
Vector
Access
Complexity
Authentication
NETWORK LOW NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
PARTIAL NONE NONE

CVE References

Description Tags Link
Microsoft Windows Graphics Component CVE-2016-3209 Information Disclosure Vulnerability cve.report (archive)
text/html
URL Logo BID 93385
Microsoft Security Bulletin MS16-120 - Critical | Microsoft Docs docs.microsoft.com
text/html
URL Logo MS MS16-120
Microsoft Graphics Component Flaws Let Remote Users Bypass ASLR Protection and Execute Arbitrary Code and Let Local Users Gain Elevated Privileges - SecurityTracker www.securitytracker.com
text/html
URL Logo SECTRACK 1036988

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationMicrosoft.net Framework3.0sp2AllAll
ApplicationMicrosoft.net Framework3.5AllAllAll
ApplicationMicrosoft.net Framework3.5.1AllAllAll
ApplicationMicrosoft.net Framework4.5.2AllAllAll
ApplicationMicrosoft.net Framework4.6AllAllAll
ApplicationMicrosoft.net Framework3.0sp2AllAll
ApplicationMicrosoft.net Framework3.5AllAllAll
ApplicationMicrosoft.net Framework3.5.1AllAllAll
ApplicationMicrosoft.net Framework4.5.2AllAllAll
ApplicationMicrosoft.net Framework4.6AllAllAll
ApplicationMicrosoftLive Meeting2007AllAllAll
ApplicationMicrosoftLive Meeting2007AllAllAll
ApplicationMicrosoftLync2010AllAllAll
ApplicationMicrosoftLync2010AllattendeeAll
ApplicationMicrosoftLync2013sp1AllAll
ApplicationMicrosoftLync2010AllAllAll
ApplicationMicrosoftLync2010AllattendeeAll
ApplicationMicrosoftLync2013sp1AllAll
ApplicationMicrosoftOffice2007sp3AllAll
ApplicationMicrosoftOffice2010sp2AllAll
ApplicationMicrosoftOffice2007sp3AllAll
ApplicationMicrosoftOffice2010sp2AllAll
ApplicationMicrosoftSilverlight5.0AllAllAll
ApplicationMicrosoftSilverlight5.0AllAllAll
ApplicationMicrosoftSkype For Business2016AllAllAll
ApplicationMicrosoftSkype For Business2016AllAllAll
Operating
System
MicrosoftWindows 10-AllAllAll
Operating
System
MicrosoftWindows 101511AllAllAll
Operating
System
MicrosoftWindows 101607AllAllAll
Operating
System
MicrosoftWindows 10-AllAllAll
Operating
System
MicrosoftWindows 101511AllAllAll
Operating
System
MicrosoftWindows 101607AllAllAll
Operating
System
MicrosoftWindows 7-sp1AllAll
Operating
System
MicrosoftWindows 7-sp1AllAll
Operating
System
MicrosoftWindows 8.1AllAllAllAll
Operating
System
MicrosoftWindows 8.1AllAllAllAll
Operating
System
MicrosoftWindows Rt 8.1-AllAllAll
Operating
System
MicrosoftWindows Rt 8.1-AllAllAll
Operating
System
MicrosoftWindows Server 2008-sp2AllAll
Operating
System
MicrosoftWindows Server 2008r2sp1AllAll
Operating
System
MicrosoftWindows Server 2008-sp2AllAll
Operating
System
MicrosoftWindows Server 2008r2sp1AllAll
Operating
System
MicrosoftWindows Server 2012-AllAllAll
Operating
System
MicrosoftWindows Server 2012r2AllAllAll
Operating
System
MicrosoftWindows Server 2012-AllAllAll
Operating
System
MicrosoftWindows Server 2012r2AllAllAll
Operating
System
MicrosoftWindows Vista-sp2AllAll
Operating
System
MicrosoftWindows Vista-sp2AllAll
ApplicationMicrosoftWord Viewer-AllAllAll
ApplicationMicrosoftWord Viewer-AllAllAll
  • cpe:2.3:a:microsoft:.net_framework:3.0:sp2:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:.net_framework:4.5.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:.net_framework:4.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:.net_framework:3.0:sp2:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:.net_framework:4.5.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:.net_framework:4.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:live_meeting:2007:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:live_meeting:2007:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:lync:2010:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:lync:2010:*:attendee:*:*:*:*:*:
  • cpe:2.3:a:microsoft:lync:2013:sp1:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:lync:2010:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:lync:2010:*:attendee:*:*:*:*:*:
  • cpe:2.3:a:microsoft:lync:2013:sp1:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:office:2007:sp3:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:office:2007:sp3:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:silverlight:5.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:silverlight:5.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:skype_for_business:2016:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:skype_for_business:2016:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:word_viewer:-:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:word_viewer:-:*:*:*:*:*:*:*: