PT-2018-9665 · Adobe+1 · Atmfd.Dll+11

Haikuo Xie

+1

·

Publicado

2018-04-10

·

Atualizado

2019-10-03

·

CVE-2018-1008

CVSS v3.1

7.0

Alta

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Windows Adobe Type Manager Font Driver (ATMFD.dll) versions prior to the fixed version Windows 7 Windows Server 2008 Windows Server 2008 R2 Windows 8.1 Windows RT 8.1 Windows Server 2012 Windows Server 2012 R2 Windows Server 2016 Windows 10 Windows 10 Servers
Description: An elevation of privilege issue exists due to the improper handling of objects in memory. This allows attackers to affect the system. The estimated number of potentially affected devices worldwide is not specified.
Recommendations: For Windows 7, apply the patch to fix the elevation of privilege vulnerability. For Windows Server 2008, apply the patch to fix the elevation of privilege vulnerability. For Windows Server 2008 R2, apply the patch to fix the elevation of privilege vulnerability. For Windows 8.1, apply the patch to fix the elevation of privilege vulnerability. For Windows RT 8.1, apply the patch to fix the elevation of privilege vulnerability. For Windows Server 2012, apply the patch to fix the elevation of privilege vulnerability. For Windows Server 2012 R2, apply the patch to fix the elevation of privilege vulnerability. For Windows Server 2016, apply the patch to fix the elevation of privilege vulnerability. For Windows 10, apply the patch to fix the elevation of privilege vulnerability. For Windows 10 Servers, apply the patch to fix the elevation of privilege vulnerability. As a temporary workaround, consider restricting access to the ATMFD.dll until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2018-1008
ZDI-18-293

Produtos afetados

Atmfd.Dll
Windows
Windows 10
Windows 10 Servers
Windows 7
Windows 8.1
Windows Rt 8.1
Windows Server 2008
Windows Server 2008 R2
Windows Server 2012
Windows Server 2012 R2
Windows Server 2016