Remote Code Execution Vulnerability in Windows Font Library by Microsoft
CVE-2018-8332
8.8HIGH
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 13 September 2018
Summary
This vulnerability enables an attacker to execute arbitrary code on affected systems by leveraging specially crafted embedded fonts processed by the Windows font library. When a victim opens a malicious document or views a webpage containing these fonts, the attacker can gain control over the system. This vulnerability affects multiple versions of Windows and Microsoft Office, highlighting the necessity for users to apply security updates promptly to mitigate potential exploitation.
Affected Version(s)
Microsoft Office 2016 Click-to-Run (C2R) for 32-bit editions
Microsoft Office 2016 Click-to-Run (C2R) for 64-bit editions
Microsoft Office 2016 for Mac
References
EPSS Score
38% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved