PT-2014-7150 · Microsoft · Windows Server 2008+8
Published
2014-11-11
·
Updated
2019-05-15
·
CVE-2014-6317
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Windows Server 2003 version SP2
Windows Vista version SP2
Windows Server 2008 versions SP2 and R2 SP1
Windows 7 version SP1
Windows 8
Windows 8.1
Windows Server 2012 versions Gold and R2
Windows RT versions Gold and 8.1
Description
A denial of service issue exists due to the improper handling of TrueType font objects in memory by the Windows kernel-mode driver. This allows remote attackers to cause a denial of service, resulting in the system stopping to respond and restarting, via a crafted TrueType font.
Recommendations
For Windows Server 2003 SP2, update to a newer version to mitigate the risk.
For Windows Vista SP2, update to a newer version to mitigate the risk.
For Windows Server 2008 SP2 and R2 SP1, update to a newer version to mitigate the risk.
For Windows 7 SP1, update to a newer version to mitigate the risk.
For Windows 8, update to a newer version to mitigate the risk.
For Windows 8.1, update to a newer version to mitigate the risk.
For Windows Server 2012 Gold and R2, update to a newer version to mitigate the risk.
For Windows RT Gold and 8.1, update to a newer version to mitigate the risk.
As a temporary workaround, consider restricting the use of TrueType fonts until a patch is available.
Fix
DoS
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows 7
Windows 8
Windows 8.1
Windows Rt
Windows Server 2003
Windows Server 2008
Windows Server 2012
Windows Vista