CVE-2016-3393
KEVmassRemote Code Execution in Microsoft Windows GDI/GDI+ Graphics Component
CISA: Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability
CVE-2016-3393 is a remote code execution vulnerability in the Windows Graphics Device Interface (GDI/GDI+), the component that renders text, images and graphics across Windows. An attacker triggers it by getting a user to visit a crafted website or otherwise view attacker-supplied content that is rendered through GDI (the CVSS vector confirms user interaction is required), and successful exploitation yields arbitrary code execution in the context of the current user. Affected software spans essentially the entire Windows estate of the era: Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 1507/1511/1607, and Windows Server 2008 SP2 and R2 SP1 and Server 2012 and 2012 R2. The flaw was patched in Microsoft's November 2016 Patch Tuesday, which fixed five zero-days being exploited in the wild, and reporting at the time attributed exploitation of this Windows graphics zero-day to the FruityArmor APT in targeted attacks. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-25), has a high EPSS score (68.7%, 99th percentile), and no public proof-of-concept is known.
What to do: Apply the November 2016 Microsoft security updates for the Windows Graphics Component to every affected Windows client and server version, per vendor instructions and CISA KEV's required action. For versions past end of support (Vista, 7, 8.1, RT 8.1, Server 2008/2012), move to a supported Windows release or apply Extended Security Updates. Until patched, discourage users from visiting untrusted websites or opening untrusted documents/images, and prioritize remediation on internet-facing servers and endpoints used by high-value users, given the documented targeted-attack use by the FruityArmor APT.
| Microsoft Windows Vista | SP2 |
| Microsoft Windows 7 | SP1 |
| Microsoft Windows 8.1 | all supported editions |
| Microsoft Windows RT 8.1 | all supported editions |
| Microsoft Windows 10 | 1507 (RTM), 1511, and 1607 |
| Microsoft Windows Server 2008 | SP2 and R2 SP1 |
| Microsoft Windows Server 2012 | Gold and R2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Graphics Component RCE Vulnerability."
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1511, windows 10 1607, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows vista
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H