Microsoft Windows TrueType Font File Code Execution

Strike ID:
E18-maz41
CVSS:
8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
3
Year:
2018

Description

This strike exploits a vulnerability in the Windows Font Library. The vulnerability is caused by improper handling of embedded fonts. A remote attacker could exploit the vulnerability to execute arbitrary code or cause a denial of service (BSOD) by enticing a user to open a specially crafted TrueType file.

CVE

References

Bid