PT-2010-4254 · Microsoft · Office+1

Carsten Book

+1

·

Published

2010-09-15

·

Updated

2023-12-07

·

CVE-2010-2738

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 Microsoft Office versions XP SP3, 2003 SP3, and 2007 SP2
Description A remote code execution issue exists due to the incorrect parsing of specific font types by Microsoft Windows and Microsoft Office. This could allow an attacker to execute arbitrary code via a crafted web site or Office document. An attacker who successfully exploits this issue could run arbitrary code as the logged-on user.
Recommendations For Microsoft Windows versions XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2, update to a version that correctly parses font types to prevent remote code execution. For Microsoft Office versions XP SP3, 2003 SP3, and 2007 SP2, update to a version that correctly parses font types to prevent remote code execution. As a temporary workaround, consider restricting the use of potentially malicious font types in Microsoft Windows and Microsoft Office until a patch is available.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-2738

Affected Products

Office
Windows