PT-2010-4254 · Microsoft · Office+1
Carsten Book
+1
·
Published
2010-09-15
·
Updated
2023-12-07
·
CVE-2010-2738
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2
Microsoft Office versions XP SP3, 2003 SP3, and 2007 SP2
Description
A remote code execution issue exists due to the incorrect parsing of specific font types by Microsoft Windows and Microsoft Office. This could allow an attacker to execute arbitrary code via a crafted web site or Office document. An attacker who successfully exploits this issue could run arbitrary code as the logged-on user.
Recommendations
For Microsoft Windows versions XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2, update to a version that correctly parses font types to prevent remote code execution.
For Microsoft Office versions XP SP3, 2003 SP3, and 2007 SP2, update to a version that correctly parses font types to prevent remote code execution.
As a temporary workaround, consider restricting the use of potentially malicious font types in Microsoft Windows and Microsoft Office until a patch is available.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office
Windows