PT-2014-7150 · Microsoft · Windows Server 2008+8

Publicado

2014-11-11

·

Atualizado

2019-05-15

·

CVE-2014-6317

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Windows Server 2003 version SP2 Windows Vista version SP2 Windows Server 2008 versions SP2 and R2 SP1 Windows 7 version SP1 Windows 8 Windows 8.1 Windows Server 2012 versions Gold and R2 Windows RT versions Gold and 8.1
Description A denial of service issue exists due to the improper handling of TrueType font objects in memory by the Windows kernel-mode driver. This allows remote attackers to cause a denial of service, resulting in the system stopping to respond and restarting, via a crafted TrueType font.
Recommendations For Windows Server 2003 SP2, update to a newer version to mitigate the risk. For Windows Vista SP2, update to a newer version to mitigate the risk. For Windows Server 2008 SP2 and R2 SP1, update to a newer version to mitigate the risk. For Windows 7 SP1, update to a newer version to mitigate the risk. For Windows 8, update to a newer version to mitigate the risk. For Windows 8.1, update to a newer version to mitigate the risk. For Windows Server 2012 Gold and R2, update to a newer version to mitigate the risk. For Windows RT Gold and 8.1, update to a newer version to mitigate the risk. As a temporary workaround, consider restricting the use of TrueType fonts until a patch is available.

Correção

DoS

Improper Validation of Array Index

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-6317

Produtos afetados

Windows
Windows 7
Windows 8
Windows 8.1
Windows Rt
Windows Server 2003
Windows Server 2008
Windows Server 2012
Windows Vista