ZeroHour

CVE-2016-7256

KEVmass

Remote Code Execution in Microsoft Windows OpenType Font Library (atmfd.dll)

CISA: Microsoft Windows Open Type Font Remote Code Execution Vulnerability

CVSS 3.1
8.8 high
EPSS
65%p99
Published
()
KEV added
AI analysis

atmfd.dll, the Adobe Type Manager (ATM) font driver in the Windows font library, improperly processes crafted OpenType fonts, allowing remote code execution. An attacker triggers the flaw by luring a user to a crafted website (or otherwise getting the user's system to parse attacker-supplied OpenType font content); no authentication is required, but user interaction is needed. Successful exploitation lets the attacker execute arbitrary code in the context of the current user, with high impact on confidentiality, integrity, and availability. The affected range spans nearly every Windows release of the era, from Windows Vista SP2 through Windows 10 1607 and Windows Server 2016, so the potentially vulnerable population is enormous. The flaw is confirmed exploited in the wild (CISA KEV, added 2022-05-25, ransomware use unknown), carries a very high EPSS (~65% chance of exploitation in 30 days, 99th percentile), and Microsoft patched it in the November 2016 security updates.

What to do: Apply Microsoft's November 2016 security update (MS16-144) or a later cumulative/monthly rollup that includes it, per the CISA KEV required action. For legacy systems still running Windows 7/8.1, Server 2008/2008 R2/2012, verify the patch (atmfd.dll updated) rather than assuming, since these OSes are past mainstream support. As interim mitigation, block untrusted OpenType fonts and avoid visiting untrusted websites or previewing untrusted files on unpatched systems.

Affected
Microsoft Windows VistaSP2
Microsoft Windows Server 2008SP2 and R2 SP1
Microsoft Windows 7SP1
Microsoft Windows 8.1all editions listed (no service pack qualifier given)
Microsoft Windows RT 8.1RT 8.1 as listed
Microsoft Windows Server 2012Gold and R2
Microsoft Windows 101507 (Gold), 1511, and 1607
Microsoft Windows Server 2016all as listed
Estimated exposure
masshundreds of millions of Windows PCs and servers (the Windows 7/8.1/10-1507-1607-era install base) — atmfd.dll shipped and ran by default on every listed Windows release, which together made up the overwhelming majority of the global Windows installed base (hundreds of millions of endpoints and servers) during the vulnerable period,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Open Type Font Remote Code Execution Vulnerability."

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1511, windows 10 1607, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016, windows vista
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news