Vulnerability record · CVE-2016-0170 · published 11 May 2016
CVE-2016-0170: Windows GDI ExtEscape buffer overflow allows remote code execution
Microsoft · Windows 10
The Windows Graphics Device Interface (GDI) mishandles a crafted document, leading to a buffer overflow in gdi32.dll's ExtEscape path that permits remote code execution. Because the flaw sits in a core graphics component reached by ordinary document rendering, it affects a broad set of Windows client and server releases.
Description
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted document, aka "Windows Graphics Component RCE Vulnerability."
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with no privileges required and only user interaction, on widely deployed Windows versions, with high EPSS despite no KEV listing.
What it is
The Windows Graphics Device Interface (GDI) mishandles a crafted document, leading to a buffer overflow in gdi32.dll's ExtEscape path that permits remote code execution. Because the flaw sits in a core graphics component reached by ordinary document rendering, it affects a broad set of Windows client and server releases.
Impact
An attacker who gets a victim to open a crafted document can execute arbitrary code in the context of the logged-on user, giving full control of confidentiality, integrity and availability on that host.
Attack surface
Reached over the network via a crafted document that the target must open or render, so user interaction is required and no prior authentication is needed (CVSS vector AV:N/AC:L/PR:N/UI:R).
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is high at roughly 0.49 (98.8th percentile), indicating elevated likelihood of attempted exploitation; reference tags are empty and provide no additional exploitation evidence.
What to do
- Apply the Microsoft MS16-055 security update for the affected Windows versions as the primary fix.
- Where patching is delayed, block or restrict opening of untrusted documents from email and web sources.
- Enforce attachment filtering and Mark-of-the-Web handling so documents from external sources are opened in a hardened context.
- Reduce user privileges so a successful exploit runs with limited rights rather than administrative access.
Detection
- Monitor for gdi32.dll crashes or buffer-overflow exceptions in document-rendering processes such as Word, Excel or the Windows shell.
- Alert on suspicious child processes spawned by document viewers or the print spooler, which can indicate post-exploitation code execution.
- Hunt for unusual document files opened from email or download directories immediately preceding process creation events.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-0170 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-0170), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.