Arbitrary code execution - CVE-2016-7082,CVE-2016-7083,CVE-2016-7084

 

Arbitrary code execution - CVE-2016-7082,CVE-2016-7083,CVE-2016-7084

Published: September 14, 2016 / Updated: April 7, 2020


Vulnerability identifier: #VU441
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Amber
CVE-ID: CVE-2016-7082,CVE-2016-7083,CVE-2016-7084
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: Public exploit is available
Vendor:
Affected software:

Detailed vulnerability description

The vulnerability allows a local user to cause arbitrary code execution on the guest system.
The weakness is caused by memory corruption error in Cortado ThinPrint ('tpview.dll'). The error made during handling of EMF files [CVE-2016-7082], TrueType fonts embedded in EMFSPOOL [CVE-2016-7083], and JPEG2000 images [CVE-2016-7084] may result in arbitrary code execution on the target system.
Successful exploitation of this vulnerability will allow a local attacker to trigger arbitrary code execution on the host system.

How to mitigate CVE-2016-7082,CVE-2016-7083,CVE-2016-7084

Update to 12.5.0.

Sources