GDI+ Information Disclosure Vulnerability in Microsoft Windows and Office Products
CVE-2016-3263

5.5MEDIUM

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
14 October 2016

Summary

The Graphics Device Interface (GDI or GDI+) in various Microsoft Windows versions and Microsoft Office products contains a vulnerability that allows remote attackers to bypass the Address Space Layout Randomization (ASLR) protection mechanism. This exposure enables the potential unauthorized access to sensitive information through unspecified vectors, compromising the privacy and security of users.

References

EPSS Score

22% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.