Remote Code Execution Vulnerability in Windows Font Library by Microsoft
CVE-2018-8332

8.8HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
13 September 2018

Summary

This vulnerability enables an attacker to execute arbitrary code on affected systems by leveraging specially crafted embedded fonts processed by the Windows font library. When a victim opens a malicious document or views a webpage containing these fonts, the attacker can gain control over the system. This vulnerability affects multiple versions of Windows and Microsoft Office, highlighting the necessity for users to apply security updates promptly to mitigate potential exploitation.

Affected Version(s)

Microsoft Office 2016 Click-to-Run (C2R) for 32-bit editions

Microsoft Office 2016 Click-to-Run (C2R) for 64-bit editions

Microsoft Office 2016 for Mac

References

EPSS Score

38% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.