← Vulnerability feed

Vulnerability record · CVE-2016-3304 · published 9 August 2016

CVE-2016-3304: Windows font library input validation flaw enables remote code execution

Microsoft · Live Meeting

The Windows font library fails to properly validate crafted embedded fonts, allowing remote code execution. It affects a wide range of Windows versions plus Office, Word Viewer, Skype for Business, Lync and Live Meeting. Because fonts are processed automatically in many document and messaging workflows, the flaw matters for both endpoint and collaboration software.

7.8 CVSS 3.0 High EPSS 51% · top 1.1% CWE-20 · Improper input validation
7.8CVSS 3.0 base score, v2 9.3
51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
8Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016, Lync 2013 SP1, Lync 2010, Lync 2010 Attendee, and Live Meeting 2007 Console allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Windows Graphics Component RCE Vulnerability," a different vulnerability than CVE-2016-3303.

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityHigh CVSS impact and a very high EPSS percentile with public exploit code, though exploitation requires user interaction and no KEV listing exists.

What it is

The Windows font library fails to properly validate crafted embedded fonts, allowing remote code execution. It affects a wide range of Windows versions plus Office, Word Viewer, Skype for Business, Lync and Live Meeting. Because fonts are processed automatically in many document and messaging workflows, the flaw matters for both endpoint and collaboration software.

Impact

An attacker who gets a crafted embedded font processed can execute arbitrary code in the context of the affected application or user. CVSS 3.0 rates confidentiality, integrity and availability impact as high.

Attack surface

Reached locally with user interaction required (CVSS vector AV:L/UI:R), typically by opening or previewing a document, message or other content containing a crafted embedded font. No privileges are required (PR:N), but the victim must trigger processing of the malicious font.

Exploitation

Not listed in CISA KEV and no ransomware use is documented, but EPSS is 0.505 (98.9th percentile) and a public Exploit-DB entry (40257) exists, indicating exploit code is publicly available.

What to do

  • Apply Microsoft security update MS16-097 for the affected Windows, Office, Lync, Skype for Business and Live Meeting products.
  • Disable or restrict embedded font processing in Office and messaging clients where feasible.
  • Block or strip embedded fonts from untrusted documents and messages at email and web gateways.
  • Upgrade or retire unsupported platforms such as Windows Vista, Windows Server 2008 and Office 2007 that no longer receive fixes.

Detection

  • Monitor for Office, Word Viewer, Lync, Skype for Business or Live Meeting processes spawning unexpected child processes such as cmd.exe or powershell.exe.
  • Alert on crashes or abnormal behavior in font-related components (e.g., fontdrvhost, gdi32, win32k) when opening documents or messages.
  • Hunt for documents and messages containing embedded fonts arriving from external or untrusted senders.
  • Review endpoint telemetry for known Exploit-DB 40257 exploitation patterns against affected applications.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-3304 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed9.8CVE-2019-0708Microsoft Remote Desktop Services use-after-free remote code executionRemote Desktop Services (formerly Terminal Services) contains a use-after-free flaw that lets an unauthenticated attacker execute code by sending spe…KEVEPSS 100%analysed9.8CVE-2017-8543Windows Search memory handling flaw allows remote code executionWindows Search fails to properly handle objects in memory, allowing an unauthenticated remote attacker to execute code on affected Windows systems. T…KEVEPSS 74%analysed9.8CVE-2015-1635Microsoft HTTP.sys remote code execution via crafted HTTP requestsHTTP.sys in multiple Windows versions fails to properly handle crafted HTTP requests, allowing remote code execution. The flaw is reachable over the …KEVEPSS 100%analysed8.8CVE-2023-35311Microsoft Outlook security feature bypass via TOCTOU race conditionCVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects …KEVEPSS 16%analysed8.8CVE-2022-41128Windows Scripting Languages out-of-bounds write allows remote code executionCVE-2022-41128 is an out-of-bounds write (CWE-787) in Windows Scripting Languages that leads to remote code execution. Microsoft rates it 8.8 HIGH wi…KEVEPSS 25%analysed8.8CVE-2021-40444Microsoft MSHTML remote code execution via malicious Office documentCVE-2021-40444 is a remote code execution flaw in the MSHTML browser rendering engine on Microsoft Windows. An attacker can embed a malicious ActiveX…KEVEPSS 97%analysed8.8CVE-2020-1020Windows Adobe Type Manager Library font parsing out-of-bounds write RCEMicrosoft Windows Adobe Type Manager Library mishandles a specially crafted multi-master font in Adobe Type 1 PostScript format, causing an out-of-bo…KEVEPSS 65%analysed

Source: NIST National Vulnerability Database (record CVE-2016-3304), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.