CVE-2016-3209
Microsoft Windows Vista SP2、Windows Server 2008 SP2 および R2 SP1、Windows 7 SP1、Windows 8.1、Windows Server 2012 Gold および R2、Windows RT 8.1、Windows 10...
- 公開済み
- 2016/10/14
- 更新済み
- 2024/08/05
- CNA の割り当て
- microsoft
- 観察された証拠
- 2016/10/20
プライマリ CVSS
nvd · CVSS 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N中 · 今後 30 日間
- パーセンタイル
- 98.6%
- モデルの日付
- 2026/09/21
EPSS は統計的な推定値であり、確実性や影響の尺度ではありません。 CVSS、KEV ステータス、暴露、環境と組み合わせます。
概要
Microsoft Windows Vista SP2、Windows Server 2008 SP2 および R2 SP1、Windows 7 SP1、Windows 8.1、Windows Server 2012 Gold および R2、Windows RT 8.1、Windows 10 Gold、1511、および 1607、Office 2007 SP3、Office 2010 SP2、Word Viewer、Skype for Business 2016、Lync 2013 SP1、Lync 2010、Lync 2010 Attendee、Live Meeting 2007 Console、.NET Framework 3.0 SP2、3.5、3.5.1、4.5.2、および 4.6、Silverlight 5 の Graphics Device Interface(別名 GDI または GDI+)は、不特定のベクターを介してリモートの攻撃者が ASLR 保護メカニズムをバイパスすることを可能にします。これは「True Type Font Parsing Information Disclosure Vulnerability」としても知られています。
ソース
1Google Security Research · windows · 2016/10/20
責任ある使用
脆弱性情報は、自分が所有しているシステム、またはテストを許可されているシステムでのみ使用してください。 Kitploit は公開研究メタデータにリンクしており、エクスプロイト コードや悪意のあるペイロードは保存しません。