60
CVE-2016-7257
—CVSS 3.0
6.5 medium
EPSS
23%p98
Published
()
Modified
Description
The GDI component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office for Mac 2011, and Office 2016 for Mac allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI Information Disclosure Vulnerability."
- Vendors
- microsoft
- Products
- office for mac, windows 7, windows server 2008, windows vista
- Weakness
- CWE-200
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N