Vulnerability record · CVE-2016-3303 · published 9 August 2016
CVE-2016-3303: Windows font library input validation flaw enables remote code execution
Microsoft · Live Meeting
The Windows font library fails to properly validate crafted embedded fonts, allowing memory corruption that can lead to arbitrary code execution. The flaw affects a wide range of Microsoft products including Windows Vista through Windows 7, Windows Server 2008, Office 2007/2010, Word Viewer, Skype for Business 2016, Lync, and Live Meeting. It is a distinct vulnerability from CVE-2016-3304.
Description
The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016, Lync 2013 SP1, Lync 2010, Lync 2010 Attendee, and Live Meeting 2007 Console allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Windows Graphics Component RCE Vulnerability," a different vulnerability than CVE-2016-3304.
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityA public exploit exists and EPSS is very high, but exploitation requires local user interaction to open a crafted file, keeping it below critical.
What it is
The Windows font library fails to properly validate crafted embedded fonts, allowing memory corruption that can lead to arbitrary code execution. The flaw affects a wide range of Microsoft products including Windows Vista through Windows 7, Windows Server 2008, Office 2007/2010, Word Viewer, Skype for Business 2016, Lync, and Live Meeting. It is a distinct vulnerability from CVE-2016-3304.
Impact
An attacker who successfully exploits this can execute arbitrary code in the context of the current user. Because the CVSS vector shows high confidentiality, integrity, and availability impact, a full compromise of the affected process and potentially the host is possible.
Attack surface
The CVSS vector is local with user interaction required (AV:L/UI:R), meaning the victim must open or render a crafted document or font file. No privileges are required (PR:N), so any user who processes the malicious content can trigger it.
Exploitation
CISA KEV does not list this CVE, but EPSS is high at roughly 0.505 (98.9th percentile), and a public Exploit-DB entry (40256) exists, indicating exploit code is available. No ransomware associations are documented.
What to do
- Apply Microsoft security bulletin MS16-097 for the affected Windows, Office, Lync, Skype for Business, and Live Meeting components.
- Disable or restrict embedded font rendering in Office and Windows where feasible until patching is complete.
- Block untrusted font files and documents from external sources at email and web gateways.
- Run affected applications with least privilege and enable exploit mitigation features such as DEP and ASLR.
- Inventory all listed products, including legacy Lync, Live Meeting, and Word Viewer, since they may be overlooked in patch cycles.
Detection
- Monitor for processes such as WINWORD.EXE, EXCEL.EXE, LYNC.EXE, or OCSMEET.EXE spawning unexpected child processes or making unusual network connections.
- Hunt for Office or Lync documents containing embedded font resources that originate from external or untrusted sources.
- Review endpoint telemetry for crashes or memory corruption in font-related DLLs (e.g., gdi32.dll, fontdrvhost.exe) following document or font rendering.
- Search for known Exploit-DB 40256 indicators or related shellcode patterns in file and memory scans.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-3303 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-3303), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.