Back

CVE-2016-7182

CRITICAL

The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007 Console allows attackers to execute arbitrary code via a crafted True Type font, aka "True Type Font Parsing Elevation of Privilege Vulnerability."

Published: Oct 14, 2016 Modified: Jun 17, 2026
CWE-20

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (19)

Vendor Product Version
microsoft live_meeting 2007
microsoft lync 2010
microsoft lync 2010
microsoft lync 2013
microsoft office 2007
microsoft office 2010
microsoft skype_for_business 2016
microsoft word_viewer -
microsoft windows_10 -
microsoft windows_10 1511
microsoft windows_10 1607
microsoft windows_7 -
microsoft windows_8.1 *
microsoft windows_rt_8.1 -
microsoft windows_server_2008 -
microsoft windows_server_2008 r2
microsoft windows_server_2012 -
microsoft windows_server_2012 r2
microsoft windows_vista -

GitHub Security Advisory GHSA-h83x-2g4x-q692

The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1;...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 30.32%

Top 2% most likely to be exploited

Threat Score 48.3 / 100

Data Sources

NVD EPSS GitHub