The issue, tracked as CVE-2016-3319, is found in the Microsoft Windows PDF Library, the default Windows utility used to open, read, and render PDF files, embedded by default in a couple of apps such as Edge.
An attacker could craft malicious code, add it to the header of a PDF file, and host the file on a Web server.
CVE-2016-3319 exploitation is trivial
If the attacker managed to social engineer a user to access the PDF file link, which can be a trivial task, the exploit code would cause a memory corruption issue, which in turn would allow the attacker to execute custom code on the Windows machine.
The issue is exacerbated by the fact that Windows 10 uses Edge as the default, out-of-the-box browser, where the vu...
SOCIAL SHARE CARD GENERATOR