Integer Overflow Vulnerability in Microsoft Windows EOT Font Engine
CVE-2010-0018

Currently unrated

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
13 January 2010

What is CVE-2010-0018?

This vulnerability arises from an integer overflow in the Embedded OpenType (EOT) Font Engine (t2embed.dll) affecting several versions of the Microsoft Windows operating system. Attackers can exploit this flaw by sending specially crafted compressed data that exploits the EOT font format, leading to potential arbitrary code execution on the affected systems. This could allow an unauthorized user to gain control over the system and execute malicious commands remotely.

References

EPSS Score

65% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.