May 25, 2022 · Applied Cybernetics Group
CVE-2016-7256 — Microsoft Windows
Microsoft Windows Open Type Font Remote Code Execution Vulnerability
- Added to KEV
2022-05-25- Federal due date
2022-06-15- Vendor
- Microsoft
- Product
- Windows
- EPSS
- 98.1th percentile (score 0.555, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2016-7256
CISA short description
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerability could take control of the affected system.
Required action
Apply updates per vendor instructions.