ID:2570 - Exploit for Arbitrary code execution - CVE-2016-7084
Published: April 7, 2020
Vulnerability identifier: #VU441
Vulnerability risk: High
CVE-ID: CVE-2016-7084
CWE-ID: CWE-119
Exploitation vector: Local access
Vulnerable software:
Link to public exploit:
Vulnerability description
The vulnerability allows a local user to cause arbitrary code execution on the guest system.
The weakness is caused by memory corruption error in Cortado ThinPrint ('tpview.dll'). The error made during handling of EMF files [CVE-2016-7082], TrueType fonts embedded in EMFSPOOL [CVE-2016-7083], and JPEG2000 images [CVE-2016-7084] may result in arbitrary code execution on the target system.
Successful exploitation of this vulnerability will allow a local attacker to trigger arbitrary code execution on the host system.
The weakness is caused by memory corruption error in Cortado ThinPrint ('tpview.dll'). The error made during handling of EMF files [CVE-2016-7082], TrueType fonts embedded in EMFSPOOL [CVE-2016-7083], and JPEG2000 images [CVE-2016-7084] may result in arbitrary code execution on the target system.
Successful exploitation of this vulnerability will allow a local attacker to trigger arbitrary code execution on the host system.
Remediation
Update to 12.5.0.