Remote Code Execution Vulnerability in Microsoft Graphics Component on Windows
CVE-2017-11762
8.8HIGH
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 13 October 2017
Summary
The Microsoft Graphics Component across various Windows platforms, including Windows Server 2008 and Windows 10, has a vulnerability that allows attackers to execute arbitrary code remotely. This occurs due to the improper handling of specially crafted embedded fonts, which could result in significant security risks if exploited by a malicious entity.
Affected Version(s)
Microsoft Graphics Component Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016
References
EPSS Score
21% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved