Windows PDF Remote Code Execution
🔗 CVE IDs covered (1)
📋 Description
A remote code execution vulnerability exists in Microsoft Windows if a user opens a specially crafted .pdf file. An attacker who successfully exploited the vulnerabilities could cause arbitrary code to execute in the context of the current user. If a user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The update addresses the vulnerabilities by modifying how Windows parses .pdf files.
🎯 Affected products12
- Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1511 for 32-bit Systems
- Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1511 for x64-based Systems
- Microsoft Edge (EdgeHTML-based) on Windows 10 for 32-bit Systems
- Microsoft Edge (EdgeHTML-based) on Windows 10 for x64-based Systems
- Windows 10 Version 1511 for 32-bit Systems
- Windows 10 Version 1511 for x64-based Systems
- Windows 10 for 32-bit Systems
- Windows 10 for x64-based Systems
- Windows 8.1 for 32-bit systems
- Windows 8.1 for x64-based systems
- Windows Server 2012
- Windows Server 2012 R2
✅ Remediation
KB3163017 (Security Update) KB3163018 (Security Update) KB3157569 (Security Update)
🔗 References (6)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2016-3203
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB3163017
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB3163018
- patchhttps://www.microsoft.com/download/details.aspx?familyid=19cd17e3-c460-4836-ae12-e953dfd14ef6
- patchhttps://www.microsoft.com/download/details.aspx?familyid=366d7855-18d7-4dcd-bc42-dcc60f8240a1
- patchhttps://www.microsoft.com/download/details.aspx?familyid=833c55d2-de1e-44f7-adfe-8d5560df78a8