CVE-2016-7256

HIGH(8.8)KEVLikely Exploited

Microsoft Windows Open Type Font Remote Code Execution Vulnerability

Description

CVE-2016-7256 is a remote code execution vulnerability in the Windows font library caused by improper handling of specially crafted embedded fonts. When the Windows font library fails to properly process a malicious OpenType font, an attacker can exploit this flaw to execute arbitrary code and take control of the affected system. The vulnerability can be triggered through web pages, documents, or any content that embeds custom fonts, making it a potent attack vector. CISA has listed CVE-2016-7256 in the Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild, and its EPSS percentile of 98.5% indicates a very high probability of exploitation.

KEV Information

Vendor
Microsoft
Product
Windows
Date Added
May 25, 2022
Due Date
June 15, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9

Affected Products

VendorProductVersion
microsoftwindows 10 1507-
microsoftwindows 10 1511-
microsoftwindows 10 1607-
microsoftwindows 7-
microsoftwindows 8.1-
microsoftwindows rt 8.1-
microsoftwindows server 2008-; r2
microsoftwindows server 2012-; r2
microsoftwindows server 2016-
microsoftwindows vista-

Multiple CVSS Assessments

Source: [email protected](Primary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References

Weakness Type

No specific CWE has been assigned to CVE-2016-7256 in the NVD database. The vulnerability involves improper handling of embedded font data in the Windows font library. When processing specially crafted font files, the library fails to properly validate font structures, leading to memory corruption that enables arbitrary code execution. This class of weakness relates to insufficient input validation in font parsing, a historically common attack surface in operating systems.

Learn more: CWE Overview

Impact Analysis

CVE-2016-7256 allows remote code execution through the Windows font library, enabling an attacker to take full control of an affected system. The vulnerability is remotely exploitable through web pages, email, or documents containing crafted embedded fonts, requiring only that a user views the malicious content. Confidentiality (High): Successful exploitation gives the attacker access to all data on the system with the privileges of the current user or the kernel, depending on the context of the font processing. Integrity (High): Full code execution allows the installation of persistent malware, modification of system files, and alteration of security configurations. Availability (High): The attacker can render the system inoperable, deploy ransomware, or use the compromised system as a pivot point for further attacks. With an EPSS percentile of 98.5%, this vulnerability has a near-certain likelihood of active exploitation, making immediate patching critical.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2016-7256 by listing it in the Known Exploited Vulnerabilities catalog, with a remediation deadline of June 15, 2022. The EPSS percentile of 98.5% places this vulnerability among the most likely to be exploited, indicating widespread exploitation activity. Font parsing vulnerabilities in Windows have historically been high-value targets for both targeted attacks and exploit kits, as the font rendering engine operates with elevated privileges in certain configurations, and font content is automatically processed when viewing web pages or documents without explicit user action beyond opening the content.

Remediation

  1. Apply Microsoft security updates per vendor instructions as required by the CISA KEV catalog. Install all relevant patches that address CVE-2016-7256 in the Windows font library.
  2. Upgrade to a current, supported version of Windows that includes modern font rendering protections. Newer Windows versions have moved font processing to a sandboxed user-mode environment, significantly reducing the impact of font parsing vulnerabilities.
  3. Block untrusted font loading using the Group Policy setting "Untrusted Font Blocking" available in Windows 10 and later, which prevents loading fonts from outside the trusted fonts directory.
  4. Deploy web content filtering and email security to detect and block content containing suspicious embedded fonts. Configure email gateways to scan attachments for malicious font content.
  5. Monitor for font-related exploitation attempts by reviewing Windows event logs for font loading errors, unexpected crashes in font rendering processes, and kernel-mode driver failures that may indicate exploitation activity.

Technical Details

CVE-2016-7256 is a memory corruption vulnerability in the Windows font library that occurs when processing specially crafted embedded fonts. The Windows font rendering subsystem parses font data structures to display text in various typefaces, and this vulnerability arises from insufficient validation of font table entries. When a malicious font with corrupted data structures is processed, the parser reads or writes memory beyond intended boundaries, corrupting critical data structures and enabling the attacker to redirect code execution. Font rendering in affected Windows versions occurs partly in kernel mode through the win32k.sys driver, meaning successful exploitation can potentially achieve kernel-level code execution. The attack can be delivered through any content that embeds fonts, including web pages with embedded web fonts, Office documents, PDF files, or any other format that supports custom font embedding.

Frequently Asked Questions

Is CVE-2016-7256 being actively exploited?

Yes, CVE-2016-7256 is actively exploited. CISA confirmed active exploitation by listing it in the Known Exploited Vulnerabilities catalog with a remediation deadline of June 15, 2022. The EPSS percentile of 98.5% further indicates near-certain exploitation activity.

What products are affected by CVE-2016-7256?

CVE-2016-7256 affects Microsoft Windows through the Windows font library. Multiple Windows versions are affected where the font library improperly handles specially crafted embedded fonts. Organizations should consult the relevant Microsoft security bulletin for specific version details.

How do I fix CVE-2016-7256?

Apply Microsoft security patches addressing this vulnerability. Upgrade to a supported Windows version with modern font sandboxing protections. Enable the "Untrusted Font Blocking" Group Policy on Windows 10 and later to prevent loading fonts from untrusted sources.

How severe is CVE-2016-7256?

CVE-2016-7256 is a remote code execution vulnerability with an EPSS percentile of 98.5%, indicating near-certain exploitation. Successful exploitation can give an attacker complete control over the affected system. Font parsing vulnerabilities are particularly severe because font rendering can occur with elevated privileges and is automatically triggered by viewing content.

CVSS Score

8.8
HIGH(8.8)

EPSS Score

EPSS Score64.83%
EPSS Percentile99.2%

Dates

PublishedNovember 10, 2016
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.