CERT-In Vulnerability Note
CIVN-2016-0312
Multiple Vulnerabilities in Microsoft Windows Graphics Component
Original Issue Date:December 14, 2016
Severity Rating: HIGH
Software Affected
- Windows Vista Service Pack 2
- Windows Vista x64 Edition Service Pack 2
- Windows Server 2008 for 32-bit and x64 based Systems Service Pack 2
- Windows Server 2008 for Itanium-based Systems Service Pack 2
- Windows 7 for 32-bit and x64-based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
- Windows 8.1 for 32-bit Systems
- Windows 8.1 for x64-based Systems
- Windows Server 2012
- Windows Server 2012 R2
- Windows RT 8.1
- Windows 10 for 32-bit and x64-based Systems
- Windows 10 Version 1511 for 32-bit and x64-based Systems
- Windows 10 Version 1607 for 32-bit and x64-based Systems
- Windows Server 2016 for x64-based Systems
- Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 for x64-based Systems Service Pack 2(Server Core installation)
- Windows Server 2008 R2 for x64-based Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 R2 for x64-based Systems Service Pack 1(Server Core installation)
- Windows Server 2012 (Server Core installation)
- Windows Server 2012 R2 (Server Core installation)
- Windows Server 2016 for x64-based Systems (Server Core installation)
Overview
Multiple vulnerabilities have been reported in Microsoft Windows which could be exploited by an attacker to gain sensitive information, execute arbitrary code and take complete control of the targeted system.
Description
1. Information Disclosure Vulnerability
(
CVE-2016-7257
)
This vulnerability exists due to improper handling of memory content by Windows GDI component. An attacker could exploit this vulnerability by creating a malicious web page or a malicious document and enticing a user to visit the malicious link or open the specially crafted document. Successful exploitation of this vulnerability could allow a remote attacker to gain sensitive information to launch further attacks.
2. Remote Code Execution Vulnerabilities
(
CVE-2016-7272
CVE-2016-7273
)
These vulnerabilities exist due to improper handling of memory objects by the Windows Graphics components. A remote attacker could exploit this vulnerability by hosting a website containing a specially crafted file and convincing the targeted user to open it or sending a specially crafted file via email and enticing the targeted user to open it. Successful exploitation of the vulnerability could allow a remote attacker to execute arbitrary code and take complete control of the targeted system.
Solution
Apply appropriate fix as mentioned in the given link:
MS16-146
Vendor Information
Microsoft
https://technet.microsoft.com/en-us/library/security/MS16-146
References
Cisco
https://tools.cisco.com/security/center/viewAlert.x?alertId=49966
https://tools.cisco.com/security/center/viewAlert.x?alertId=49967
https://tools.cisco.com/security/center/viewAlert.x?alertId=49968
Security Tracker
http://securitytracker.com/id/1037438
CVE Name
CVE-2016-7257
CVE-2016-7272
CVE-2016-7273
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|