#VU441 Arbitrary code execution - CVE-2016-7082,CVE-2016-7083,CVE-2016-7084

 

#VU441 Arbitrary code execution - CVE-2016-7082,CVE-2016-7083,CVE-2016-7084

Published: September 14, 2016 / Updated: April 7, 2020


Vulnerability identifier: #VU441
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Amber
CVE-ID: CVE-2016-7082,CVE-2016-7083,CVE-2016-7084
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: Public exploit is available
Vulnerable software:
Software vendor:

Description

The vulnerability allows a local user to cause arbitrary code execution on the guest system.
The weakness is caused by memory corruption error in Cortado ThinPrint ('tpview.dll'). The error made during handling of EMF files [CVE-2016-7082], TrueType fonts embedded in EMFSPOOL [CVE-2016-7083], and JPEG2000 images [CVE-2016-7084] may result in arbitrary code execution on the target system.
Successful exploitation of this vulnerability will allow a local attacker to trigger arbitrary code execution on the host system.

Remediation

Update to 12.5.0.

External links