PT-2011-2031 · Microsoft · Windows
Adam Twardoch
·
Published
2011-04-13
·
Updated
2023-12-07
·
CVE-2011-0034
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions prior to the fixed version
Description
A remote code execution issue exists due to improper parsing of specially crafted OpenType fonts by the OpenType Font (OTF) driver. This allows attackers to execute arbitrary code in kernel mode, enabling them to install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations
For Microsoft Windows versions prior to the fixed version, update to the latest version to resolve the issue.
As a temporary workaround, consider restricting access to OpenType fonts from untrusted sources until a patch is available.
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows