Information Disclosure Vulnerability in Microsoft Windows EOT Font Engine
CVE-2018-0755
5.5MEDIUM
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 15 February 2018
Summary
The vulnerability in the Microsoft Windows Embedded OpenType (EOT) font engine arises from improper handling of embedded fonts, leading to potential information disclosure. This flaw could allow attackers to gain unauthorized access to sensitive information by exploiting the way the EOT font engine processes font data in affected versions of Microsoft Windows 7 SP1 and Windows Server 2008 R2.
Affected Version(s)
Microsoft Windows Embedded OpenType (EOT) font engine Windows 7 SP1 and Windows Server 2008 R2
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved