Microsoft Windows GDI+ Information Disclosure (MS16-120: CVE-2016-3263; CVE-2016-3263)

An information disclosure vulnerability has been reported in Microsoft Windows. The vulnerability is due to an error in the way the True Type Font (TTF) driver handles objects in memory. A remote attacker could exploit this vulnerability by enticing a target user to open a specially crafted EMF file.

Leave a Reply