CVE Tools

Description

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; Live Meeting 2007 Console; .NET Framework 3.0 SP2, 3.5, 3.5.1, 4.5.2, and 4.6; and Silverlight 5 allows remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "True Type Font Parsing Information Disclosure Vulnerability."

In plain language

AI Worth attention

This Windows-related flaw can reveal small amounts of secret computer memory when someone tricks you into opening a document with a bad font, so most small businesses should be careful with untrusted files but it’s not a common “instant” remote attack.

Executive summary

In Microsoft Windows GDI/GDI+ TrueType font parsing, a user-opening step can disclose memory contents (CWE-200) that can weaken defenses like ASLR; the issue affects multiple Microsoft components such as .NET Framework, Microsoft Office/Word Viewer, Skype for Business, Lync, Live Meeting, and Silverlight.

If affected, business impact
Sensitive memory information leakGreater chance of follow-up attacksCompromise from malicious documents

What to do now

  1. Check whether your business uses Windows 7 or Windows 10, and whether you rely on Office/Word Viewer, .NET Framework, Live Meeting/Lync/Skype for Business, or Silverlight.
  2. Identify where users open files from outside your company (email attachments, downloads, shared documents) and confirm you don’t routinely open untrusted documents with embedded fonts.
  3. Block or quarantine documents and files from unknown/untrusted sources (especially ones containing fonts) until you can apply vendor guidance.
  4. Confirm you are up to date with Microsoft security updates for the affected products, noting that no specific fixed version is identified in the provided information.
  5. Tell users to avoid opening unexpected attachments or content that prompts them to view documents/preview content from unknown sources.
May need vendor / contractor work

CVSS Vector Breakdown

AV:LAC:LPR:NUI:RS:UC:HI:NA:N
Exploitability
AV:LAttack Vector
Local
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:RUser Interaction
Required
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:NIntegrity
None
A:NAvailability
None

Weaknesses

Affected Products

and 7 more affected products View all →

Exploitability

No known exploits, KEV entries, or remediation guidance available for this vulnerability yet.

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Collection
View detailed technique mapping

References

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2016-3209 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store