CVE-2016-7257: Microsoft Office For Mac
Medium severity, CVSS 6.5. EPSS: 22.5% chance of exploitation in the next 30 days.
The GDI component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office for Mac 2011, and Office 2016 for Mac allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI Information Disclosure Vulnerability."
Affected products
- Microsoft Office For Mac: version 2011 only; version 2016 only
- Microsoft Windows 7: any version
- Microsoft Windows Server 2008: any version; version r2 only
- Microsoft Windows Vista: any version
Published 2016-12-20. Last modified 2026-06-17.