Microsoft Windows TrueType Font File Parsing Vulnerability

Strike ID:
E12-07801
CVSS:
10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
1
Year:
2010

Description

This strike exploits a vulnerability in the Windows Kernel-Mode driver caused by improper handling of memory objects while parsing TrueType fonts. A remote attacker could exploit the vulnerability to execute arbitrary code or cause a denial of service (BSOD) by enticing a user to open a specially crafted TrueType file.

CVE

Bid