AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2016-7257

MEDIUM · CVSS 6.5 EPSS 22.50%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2016-12-20 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2016-7257
Severity
MEDIUM
CVSS
6.5
EPSS
22.50%
Microsoft Windows Office

Original Filing — NVD Description

The GDI component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office for Mac 2011, and Office 2016 for Mac allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI Information Disclosure Vulnerability."