Microsoft Windows TrueType Font File Integer Overflow

Strike ID:
E18-maz42
CVSS:
8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
6
Year:
2018

Description

This strike exploits a vulnerability in the Windows Font Library. The vulnerability is caused by improper handling of a Format 12 mapping tables in a TrueType Font file. A remote attacker could exploit the vulnerability to execute arbitrary code or cause a denial of service by enticing a user to open a specially crafted TrueType file.

CVE

References

Bid