GDI+ Information Disclosure in Microsoft Windows and Office Products
CVE-2016-3262
5.5MEDIUM
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 14 October 2016
Summary
The vulnerability in Graphics Device Interface (GDI or GDI+) allows remote attackers to potentially bypass Address Space Layout Randomization (ASLR) via unspecified vectors. This issue may facilitate information disclosure, impacting a range of Microsoft products including various versions of Windows and the Office suite. It poses a significant risk as it can be exploited without any user interaction, thereby enabling remote threats to compromise system integrity and user data.
References
EPSS Score
22% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved