Information Disclosure Vulnerability in Microsoft Windows EOT Font Engine
CVE-2018-0755

5.5MEDIUM

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
15 February 2018

Summary

The vulnerability in the Microsoft Windows Embedded OpenType (EOT) font engine arises from improper handling of embedded fonts, leading to potential information disclosure. This flaw could allow attackers to gain unauthorized access to sensitive information by exploiting the way the EOT font engine processes font data in affected versions of Microsoft Windows 7 SP1 and Windows Server 2008 R2.

Affected Version(s)

Microsoft Windows Embedded OpenType (EOT) font engine Windows 7 SP1 and Windows Server 2008 R2

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.