A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2016-7256

Microsoft Windows Open Type Font Remote Code Execution Vulnerability

Published
2022-05-25
Modified
2026-07-31
Sources
cisa-kev

Summary

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerability could take control of the affected system.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.