May 25, 2022 · Applied Cybernetics Group
CVE-2016-3393 — Microsoft Windows
Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability
- Added to KEV
2022-05-25- Federal due date
2022-06-15- Vendor
- Microsoft
- Product
- Windows
- EPSS
- 98.1th percentile (score 0.557, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2016-3393
CISA short description
A remote code execution vulnerability exists due to the way the Windows GDI component handles objects in the memory. An attacker who successfully exploits this vulnerability could take control of the affected system.
Required action
Apply updates per vendor instructions.