vulnerability

MS16-026: Security Update for Graphic Fonts to Address Remote Code Execution (3143148)

Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
Published
Mar 8, 2016
Added
Mar 8, 2016
Modified
Jul 28, 2025

Description

A denial of service vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts. For all systems except Windows 10, an attacker who successfully exploited the vulnerability could cause a denial of service condition. For systems running Windows 10, an attacker who successfully exploited the vulnerability could potentially cause the application to stop responding instead of the system.

Solutions

WINDOWS-HOTFIX-MS16-023-0c7e9829-cc88-4af8-ae95-e2823ab2cbfaWINDOWS-HOTFIX-MS16-023-3f5f2fab-88aa-4fbf-975d-94424a363208WINDOWS-HOTFIX-MS16-023-62cef694-cd47-4d46-be15-e0a592991d07WINDOWS-HOTFIX-MS16-023-a52756d1-e676-45c3-8fa3-af607ba9a62eWINDOWS-HOTFIX-MS16-026-04ea041f-63e1-4c25-b357-be79c6a29660WINDOWS-HOTFIX-MS16-026-18c3ca8c-b318-4604-9e36-6c62b80a23d5WINDOWS-HOTFIX-MS16-026-3d6c8197-3c4f-46dd-bd97-25028ce9308fWINDOWS-HOTFIX-MS16-026-3fe4312b-b370-4464-aa46-498a94e81961WINDOWS-HOTFIX-MS16-026-4b308ba7-4422-4c64-9cd5-9ee72547adafWINDOWS-HOTFIX-MS16-026-4f41d8b6-a158-4670-ab0c-2cd56600b88aWINDOWS-HOTFIX-MS16-026-57e66200-26e7-4996-8096-dea63cd087faWINDOWS-HOTFIX-MS16-026-5ea8b325-9bb6-45d8-a388-2e77601f506bWINDOWS-HOTFIX-MS16-026-5f6d7431-c76e-435a-9e1a-d829fff2523bWINDOWS-HOTFIX-MS16-026-73ece136-fb60-4335-b2fd-1b98aa3c0637WINDOWS-HOTFIX-MS16-026-792375c2-bc6a-4f53-a0f4-b4a7f59b087fWINDOWS-HOTFIX-MS16-026-7d2ea465-0534-4147-8e11-01cc1c896aa3WINDOWS-HOTFIX-MS16-026-9d4be710-ecc9-4e8b-b1ff-a93a6624c789WINDOWS-HOTFIX-MS16-026-b513bf12-468b-4718-a841-1165a38a501dWINDOWS-HOTFIX-MS16-026-bf86e51d-964b-48aa-b532-4350232cc79fWINDOWS-HOTFIX-MS16-026-d06c3248-ff7e-4fc8-bf80-c48365450b91WINDOWS-HOTFIX-MS16-026-e46e824c-a60b-4196-bb81-2066ccf97aacWINDOWS-HOTFIX-MS16-026-ed5637b8-19ec-44d9-a19c-1918e41d75e8
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.