Vulnerability record · CVE-2016-3304 · published 9 August 2016
CVE-2016-3304: Windows font library input validation flaw enables remote code execution
Microsoft · Live Meeting
The Windows font library fails to properly validate crafted embedded fonts, allowing remote code execution. It affects a wide range of Windows versions plus Office, Word Viewer, Skype for Business, Lync and Live Meeting. Because fonts are processed automatically in many document and messaging workflows, the flaw matters for both endpoint and collaboration software.
Description
The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016, Lync 2013 SP1, Lync 2010, Lync 2010 Attendee, and Live Meeting 2007 Console allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Windows Graphics Component RCE Vulnerability," a different vulnerability than CVE-2016-3303.
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityHigh CVSS impact and a very high EPSS percentile with public exploit code, though exploitation requires user interaction and no KEV listing exists.
What it is
The Windows font library fails to properly validate crafted embedded fonts, allowing remote code execution. It affects a wide range of Windows versions plus Office, Word Viewer, Skype for Business, Lync and Live Meeting. Because fonts are processed automatically in many document and messaging workflows, the flaw matters for both endpoint and collaboration software.
Impact
An attacker who gets a crafted embedded font processed can execute arbitrary code in the context of the affected application or user. CVSS 3.0 rates confidentiality, integrity and availability impact as high.
Attack surface
Reached locally with user interaction required (CVSS vector AV:L/UI:R), typically by opening or previewing a document, message or other content containing a crafted embedded font. No privileges are required (PR:N), but the victim must trigger processing of the malicious font.
Exploitation
Not listed in CISA KEV and no ransomware use is documented, but EPSS is 0.505 (98.9th percentile) and a public Exploit-DB entry (40257) exists, indicating exploit code is publicly available.
What to do
- Apply Microsoft security update MS16-097 for the affected Windows, Office, Lync, Skype for Business and Live Meeting products.
- Disable or restrict embedded font processing in Office and messaging clients where feasible.
- Block or strip embedded fonts from untrusted documents and messages at email and web gateways.
- Upgrade or retire unsupported platforms such as Windows Vista, Windows Server 2008 and Office 2007 that no longer receive fixes.
Detection
- Monitor for Office, Word Viewer, Lync, Skype for Business or Live Meeting processes spawning unexpected child processes such as cmd.exe or powershell.exe.
- Alert on crashes or abnormal behavior in font-related components (e.g., fontdrvhost, gdi32, win32k) when opening documents or messages.
- Hunt for documents and messages containing embedded fonts arriving from external or untrusted senders.
- Review endpoint telemetry for known Exploit-DB 40257 exploitation patterns against affected applications.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-3304 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-3304), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.