GDI+ Information Disclosure in Microsoft Windows and Office Products
CVE-2016-3262

5.5MEDIUM

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
14 October 2016

Summary

The vulnerability in Graphics Device Interface (GDI or GDI+) allows remote attackers to potentially bypass Address Space Layout Randomization (ASLR) via unspecified vectors. This issue may facilitate information disclosure, impacting a range of Microsoft products including various versions of Windows and the Office suite. It poses a significant risk as it can be exploited without any user interaction, thereby enabling remote threats to compromise system integrity and user data.

References

EPSS Score

22% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.