Back
CVE-2016-7182
CRITICAL
The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007 Console allows attackers to execute arbitrary code via a crafted True Type font, aka "True Type Font Parsing Elevation of Privilege Vulnerability."
Published: Oct 14, 2016
Modified: Jun 17, 2026
CWE-20
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (19)
| Vendor | Product | Version |
|---|---|---|
| microsoft | live_meeting | 2007 |
| microsoft | lync | 2010 |
| microsoft | lync | 2010 |
| microsoft | lync | 2013 |
| microsoft | office | 2007 |
| microsoft | office | 2010 |
| microsoft | skype_for_business | 2016 |
| microsoft | word_viewer | - |
| microsoft | windows_10 | - |
| microsoft | windows_10 | 1511 |
| microsoft | windows_10 | 1607 |
| microsoft | windows_7 | - |
| microsoft | windows_8.1 | * |
| microsoft | windows_rt_8.1 | - |
| microsoft | windows_server_2008 | - |
| microsoft | windows_server_2008 | r2 |
| microsoft | windows_server_2012 | - |
| microsoft | windows_server_2012 | r2 |
| microsoft | windows_vista | - |
GitHub Security Advisory GHSA-h83x-2g4x-q692
The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1;...
References (6)
- http://www.securityfocus.com/bid/93395
- http://www.securitytracker.com/id/1036988
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-120
- http://www.securityfocus.com/bid/93395
- http://www.securitytracker.com/id/1036988
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-120
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
30.32%
Top 2% most likely to be exploited
Threat Score
48.3 / 100
Data Sources
NVD
EPSS
GitHub