Microsoft Windows GDI Component Information Disclosure (MS16-106: CVE-2016-3355; CVE-2016-3355)

An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory. A remote attacker could exploit this vulnerability by enticing a target user to open a malicious executable file. Successful exploitation of this issue can lead to local privilege escalation.

Leave a Reply