CVE-2016-7256
KEVmassRemote Code Execution in Microsoft Windows OpenType Font Library (atmfd.dll)
CISA: Microsoft Windows Open Type Font Remote Code Execution Vulnerability
atmfd.dll, the Adobe Type Manager (ATM) font driver in the Windows font library, improperly processes crafted OpenType fonts, allowing remote code execution. An attacker triggers the flaw by luring a user to a crafted website (or otherwise getting the user's system to parse attacker-supplied OpenType font content); no authentication is required, but user interaction is needed. Successful exploitation lets the attacker execute arbitrary code in the context of the current user, with high impact on confidentiality, integrity, and availability. The affected range spans nearly every Windows release of the era, from Windows Vista SP2 through Windows 10 1607 and Windows Server 2016, so the potentially vulnerable population is enormous. The flaw is confirmed exploited in the wild (CISA KEV, added 2022-05-25, ransomware use unknown), carries a very high EPSS (~65% chance of exploitation in 30 days, 99th percentile), and Microsoft patched it in the November 2016 security updates.
What to do: Apply Microsoft's November 2016 security update (MS16-144) or a later cumulative/monthly rollup that includes it, per the CISA KEV required action. For legacy systems still running Windows 7/8.1, Server 2008/2008 R2/2012, verify the patch (atmfd.dll updated) rather than assuming, since these OSes are past mainstream support. As interim mitigation, block untrusted OpenType fonts and avoid visiting untrusted websites or previewing untrusted files on unpatched systems.
| Microsoft Windows Vista | SP2 |
| Microsoft Windows Server 2008 | SP2 and R2 SP1 |
| Microsoft Windows 7 | SP1 |
| Microsoft Windows 8.1 | all editions listed (no service pack qualifier given) |
| Microsoft Windows RT 8.1 | RT 8.1 as listed |
| Microsoft Windows Server 2012 | Gold and R2 |
| Microsoft Windows 10 | 1507 (Gold), 1511, and 1607 |
| Microsoft Windows Server 2016 | all as listed |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Open Type Font Remote Code Execution Vulnerability."
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1511, windows 10 1607, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016, windows vista
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H