{"id":"CVE-2016-7256","aliases":[],"url":"https://o3.security/vulnerability/CVE-2016-7256","summary":"atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,…","details":"atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka \"Open Type Font Remote Code Execution Vulnerability.\"","published":"2016-11-10T06:16:00.000Z","modified":"2025-10-21T23:55:48.377Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":{"score":0.64835,"percentile":0.99184,"asOf":"2026-08-26"},"cisaKev":{"dateAdded":"2022-05-25","dueDate":"2022-06-15","knownRansomwareCampaignUse":false},"exploitsKnown":3,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://twitter.com/da5ch0/status/820161895269277696"},{"type":"WEB","url":"http://www.securitytracker.com/id/1037243"},{"type":"ADVISORY","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-132"},{"type":"WEB","url":"http://www.securityfocus.com/bid/94156"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-7256"}],"provenance":{"sources":["OSV.dev","NVD","CISA KEV","FIRST.org (EPSS)"],"lastVerified":"2025-10-21T23:55:48.377Z"}}