← Vulnerability feed

Vulnerability record · CVE-2016-3303 · published 9 August 2016

CVE-2016-3303: Windows font library input validation flaw enables remote code execution

Microsoft · Live Meeting

The Windows font library fails to properly validate crafted embedded fonts, allowing memory corruption that can lead to arbitrary code execution. The flaw affects a wide range of Microsoft products including Windows Vista through Windows 7, Windows Server 2008, Office 2007/2010, Word Viewer, Skype for Business 2016, Lync, and Live Meeting. It is a distinct vulnerability from CVE-2016-3304.

7.8 CVSS 3.0 High EPSS 51% · top 1.1% CWE-20 · Improper input validation
7.8CVSS 3.0 base score, v2 9.3
51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
8Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016, Lync 2013 SP1, Lync 2010, Lync 2010 Attendee, and Live Meeting 2007 Console allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Windows Graphics Component RCE Vulnerability," a different vulnerability than CVE-2016-3304.

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityA public exploit exists and EPSS is very high, but exploitation requires local user interaction to open a crafted file, keeping it below critical.

What it is

The Windows font library fails to properly validate crafted embedded fonts, allowing memory corruption that can lead to arbitrary code execution. The flaw affects a wide range of Microsoft products including Windows Vista through Windows 7, Windows Server 2008, Office 2007/2010, Word Viewer, Skype for Business 2016, Lync, and Live Meeting. It is a distinct vulnerability from CVE-2016-3304.

Impact

An attacker who successfully exploits this can execute arbitrary code in the context of the current user. Because the CVSS vector shows high confidentiality, integrity, and availability impact, a full compromise of the affected process and potentially the host is possible.

Attack surface

The CVSS vector is local with user interaction required (AV:L/UI:R), meaning the victim must open or render a crafted document or font file. No privileges are required (PR:N), so any user who processes the malicious content can trigger it.

Exploitation

CISA KEV does not list this CVE, but EPSS is high at roughly 0.505 (98.9th percentile), and a public Exploit-DB entry (40256) exists, indicating exploit code is available. No ransomware associations are documented.

What to do

  • Apply Microsoft security bulletin MS16-097 for the affected Windows, Office, Lync, Skype for Business, and Live Meeting components.
  • Disable or restrict embedded font rendering in Office and Windows where feasible until patching is complete.
  • Block untrusted font files and documents from external sources at email and web gateways.
  • Run affected applications with least privilege and enable exploit mitigation features such as DEP and ASLR.
  • Inventory all listed products, including legacy Lync, Live Meeting, and Word Viewer, since they may be overlooked in patch cycles.

Detection

  • Monitor for processes such as WINWORD.EXE, EXCEL.EXE, LYNC.EXE, or OCSMEET.EXE spawning unexpected child processes or making unusual network connections.
  • Hunt for Office or Lync documents containing embedded font resources that originate from external or untrusted sources.
  • Review endpoint telemetry for crashes or memory corruption in font-related DLLs (e.g., gdi32.dll, fontdrvhost.exe) following document or font rendering.
  • Search for known Exploit-DB 40256 indicators or related shellcode patterns in file and memory scans.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-3303 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed9.8CVE-2019-0708Microsoft Remote Desktop Services use-after-free remote code executionRemote Desktop Services (formerly Terminal Services) contains a use-after-free flaw that lets an unauthenticated attacker execute code by sending spe…KEVEPSS 100%analysed9.8CVE-2017-8543Windows Search memory handling flaw allows remote code executionWindows Search fails to properly handle objects in memory, allowing an unauthenticated remote attacker to execute code on affected Windows systems. T…KEVEPSS 74%analysed9.8CVE-2015-1635Microsoft HTTP.sys remote code execution via crafted HTTP requestsHTTP.sys in multiple Windows versions fails to properly handle crafted HTTP requests, allowing remote code execution. The flaw is reachable over the …KEVEPSS 100%analysed8.8CVE-2023-35311Microsoft Outlook security feature bypass via TOCTOU race conditionCVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects …KEVEPSS 16%analysed8.8CVE-2022-41128Windows Scripting Languages out-of-bounds write allows remote code executionCVE-2022-41128 is an out-of-bounds write (CWE-787) in Windows Scripting Languages that leads to remote code execution. Microsoft rates it 8.8 HIGH wi…KEVEPSS 25%analysed8.8CVE-2021-40444Microsoft MSHTML remote code execution via malicious Office documentCVE-2021-40444 is a remote code execution flaw in the MSHTML browser rendering engine on Microsoft Windows. An attacker can embed a malicious ActiveX…KEVEPSS 97%analysed8.8CVE-2020-1020Windows Adobe Type Manager Library font parsing out-of-bounds write RCEMicrosoft Windows Adobe Type Manager Library mishandles a specially crafted multi-master font in Adobe Type 1 PostScript format, causing an out-of-bo…KEVEPSS 65%analysed

Source: NIST National Vulnerability Database (record CVE-2016-3303), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.