CVE-2016-3396

Published on: 10/13/2016 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:02 PM UTC

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Certain versions of Live Meeting from Microsoft contain the following vulnerability:

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007 Console allows remote attackers to execute arbitrary code via a crafted embedded font, aka "GDI+ Remote Code Execution Vulnerability."

  • CVE-2016-3396 has been assigned by [email protected] to track the vulnerability - currently rated as HIGH severity.

CVSS3 Score: 7.8 - HIGH

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
LOCAL LOW NONE REQUIRED
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED HIGH HIGH HIGH

CVSS2 Score: 9.3 - HIGH

Access
Vector
Access
Complexity
Authentication
NETWORK MEDIUM NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
COMPLETE COMPLETE COMPLETE

CVE References

Description Tags Link
Microsoft Security Bulletin MS16-120 - Critical | Microsoft Docs docs.microsoft.com
text/html
URL Logo MS MS16-120
Microsoft Graphics Component Flaws Let Remote Users Bypass ASLR Protection and Execute Arbitrary Code and Let Local Users Gain Elevated Privileges - SecurityTracker www.securitytracker.com
text/html
URL Logo SECTRACK 1036988
Microsoft Windows Graphics Component CVE-2016-3396 Remote Code Execution Vulnerability cve.report (archive)
text/html
URL Logo BID 93380

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationMicrosoftLive Meeting2007AllAllAll
ApplicationMicrosoftLive Meeting2007AllAllAll
ApplicationMicrosoftLync2010AllAllAll
ApplicationMicrosoftLync2010AllattendeeAll
ApplicationMicrosoftLync2013sp1AllAll
ApplicationMicrosoftLync2010AllAllAll
ApplicationMicrosoftLync2010AllattendeeAll
ApplicationMicrosoftLync2013sp1AllAll
ApplicationMicrosoftOffice2007sp3AllAll
ApplicationMicrosoftOffice2010sp2AllAll
ApplicationMicrosoftOffice2007sp3AllAll
ApplicationMicrosoftOffice2010sp2AllAll
ApplicationMicrosoftSkype For Business2016AllAllAll
ApplicationMicrosoftSkype For Business2016AllAllAll
Operating
System
MicrosoftWindows 10-AllAllAll
Operating
System
MicrosoftWindows 101511AllAllAll
Operating
System
MicrosoftWindows 101607AllAllAll
Operating
System
MicrosoftWindows 10-AllAllAll
Operating
System
MicrosoftWindows 101511AllAllAll
Operating
System
MicrosoftWindows 101607AllAllAll
Operating
System
MicrosoftWindows 7-sp1AllAll
Operating
System
MicrosoftWindows 7-sp1AllAll
Operating
System
MicrosoftWindows 8.1AllAllAllAll
Operating
System
MicrosoftWindows 8.1AllAllAllAll
Operating
System
MicrosoftWindows Rt 8.1-AllAllAll
Operating
System
MicrosoftWindows Rt 8.1-AllAllAll
Operating
System
MicrosoftWindows Server 2008-sp2AllAll
Operating
System
MicrosoftWindows Server 2008r2sp1AllAll
Operating
System
MicrosoftWindows Server 2008-sp2AllAll
Operating
System
MicrosoftWindows Server 2008r2sp1AllAll
Operating
System
MicrosoftWindows Server 2012-AllAllAll
Operating
System
MicrosoftWindows Server 2012r2AllAllAll
Operating
System
MicrosoftWindows Server 2012-AllAllAll
Operating
System
MicrosoftWindows Server 2012r2AllAllAll
Operating
System
MicrosoftWindows Vista-sp2AllAll
Operating
System
MicrosoftWindows Vista-sp2AllAll
ApplicationMicrosoftWord Viewer-AllAllAll
ApplicationMicrosoftWord Viewer-AllAllAll
  • cpe:2.3:a:microsoft:live_meeting:2007:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:live_meeting:2007:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:lync:2010:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:lync:2010:*:attendee:*:*:*:*:*:
  • cpe:2.3:a:microsoft:lync:2013:sp1:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:lync:2010:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:lync:2010:*:attendee:*:*:*:*:*:
  • cpe:2.3:a:microsoft:lync:2013:sp1:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:office:2007:sp3:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:office:2007:sp3:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:skype_for_business:2016:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:skype_for_business:2016:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:word_viewer:-:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:word_viewer:-:*:*:*:*:*:*:*: