CVE-2016-3393 is a critical Remote Code Execution (RCE) vulnerability affecting the Graphics Device Interface (GDI/GDI+) component across multiple Microsoft Windows versions, including Vista, 7, 8.1, 10, and various Server editions. This high-severity flaw (CVSS 7.8) allows remote attackers to execute arbitrary code with low attack complexity by enticing a user to visit a crafted website, leading to high impact on confidentiality, integrity, and availability. The vulnerability has been actively exploited in the wild, notably by the "FruityArmor" APT group, despite no public exploit modules being readily available. Its high EPSS score and significant media coverage underscore its severe risk and the urgent need for patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.