RULE(RULE ID:320716)

Rule General Information
Release Date: 2018-04-16
Rule Name: WEB-APP Microsoft Graphics Component CREATECOLORSPACE Filesystem Information Disclosure Vulnerability (CVE-2016-0168)
Severity:
CVE ID:
Rule Protection Details
Description: GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to obtain sensitive information via a crafted document, aka "Windows Graphics Component Information Disclosure Vulnerability".
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows
Reference: http://packetstormsecurity.com/files/137094/Microsoft-Windows-gdi32.dll-Information-Disclosure.html
MicrosoftSecurityBulletin:MS16-055
SecurityFocusBID:89862
SecurityTrackerID:1035823
Solutions
Microsoft has released a patch MS16-055 to eliminate the vulnerability. The patch can be downloaded at:
http://technet.microsoft.com/security/bulletin/MS16-055