PT-2014-7150 · Microsoft · Windows Server 2008+8
Publicado
2014-11-11
·
Atualizado
2019-05-15
·
CVE-2014-6317
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Windows Server 2003 version SP2
Windows Vista version SP2
Windows Server 2008 versions SP2 and R2 SP1
Windows 7 version SP1
Windows 8
Windows 8.1
Windows Server 2012 versions Gold and R2
Windows RT versions Gold and 8.1
Description
A denial of service issue exists due to the improper handling of TrueType font objects in memory by the Windows kernel-mode driver. This allows remote attackers to cause a denial of service, resulting in the system stopping to respond and restarting, via a crafted TrueType font.
Recommendations
For Windows Server 2003 SP2, update to a newer version to mitigate the risk.
For Windows Vista SP2, update to a newer version to mitigate the risk.
For Windows Server 2008 SP2 and R2 SP1, update to a newer version to mitigate the risk.
For Windows 7 SP1, update to a newer version to mitigate the risk.
For Windows 8, update to a newer version to mitigate the risk.
For Windows 8.1, update to a newer version to mitigate the risk.
For Windows Server 2012 Gold and R2, update to a newer version to mitigate the risk.
For Windows RT Gold and 8.1, update to a newer version to mitigate the risk.
As a temporary workaround, consider restricting the use of TrueType fonts until a patch is available.
Correção
DoS
Improper Validation of Array Index
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Windows
Windows 7
Windows 8
Windows 8.1
Windows Rt
Windows Server 2003
Windows Server 2008
Windows Server 2012
Windows Vista