CVE-2016-7256CISA KEV
Microsoft Windows Open Type Font Remote Code Execution Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerability could take control of the affected system.
- Product
- Windows
- Added to KEV
- 25 May 2022
- Federal remediation due
- 15 Jun 2022
- Known ransomware use
- Not reported