MS.Windows.True.Type.Font.Parsing.Code.Execution

description-logoDescription

This indicates an attack attempt against a Buffer Overflow vulnerability in Microsoft Windows.
The vulnerability is caused by an error when the vulnerable software handles a malicious TrueType font file. A remote attacker may be able to exploit this to execute arbitrary code within the context of the application, via a crafted TrueType font file.

affected-products-logoAffected Products

Windows XP Service Pack 3
(Tablet PC Edition 2005 only)
Windows XP Service Pack 3
Windows XP Professional x64 Edition Service Pack 2
Windows Server 2003
Windows Server 2003 Service Pack 2
Windows Server 2003 x64 Edition Service Pack 2
Windows Server 2003 with SP2 for Itanium-based Systems
Windows Vista
Windows Vista Service Pack 2
Windows Vista x64 Edition Service Pack 2
Windows Server 2008
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for Itanium-based Systems Service Pack 2
Windows 7 for 32-bit Systems
Windows 7 for 32-bit Systems Service Pack 1
Windows 7 for x64-based Systems
Windows 7 for x64-based Systems Service Pack 1
Windows Server 2008 R2
Windows Server 2008 R2 for x64-based Systems
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for Itanium-based Systems
Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2 when installed on Windows XP Service Pack 3
Microsoft .NET Framework 3.0 Service Pack 2 when installed on Windows XP Professional x64 Edition Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2 when installed on Windows Server 2003 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2 when installed on Windows Server 2003 x64 Edition Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2 on Windows Vista Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2 on Windows Vista x64 Edition Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2
Microsoft .NET Framework 3.5.1 on Windows 7 for 32-bit Systems
Microsoft .NET Framework 3.5.1 on Windows 7 for 32-bit Systems Service Pack 1
Microsoft .NET Framework 3.5.1 on Windows 7 for x64-based Systems
Microsoft .NET Framework 3.5.1 on Windows 7 for x64-based Systems Service Pack 1
Microsoft .NET Framework 3.5.1 on Windows Server 2008 R2 for x64-based Systems
Microsoft .NET Framework 3.5.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1
Microsoft .NET Framework 4
Microsoft .NET Framework 4 when installed on Windows XP Service Pack 3
Microsoft .NET Framework 4 when installed on Windows XP Professional x64 Edition Service Pack 2
Microsoft .NET Framework 4 when installed on Windows Server 2003 Service Pack 2
Microsoft .NET Framework 4 when installed on Windows Server 2003 x64 Edition Service Pack 2
Microsoft .NET Framework 4 when installed on Windows Vista Service Pack 2
Microsoft .NET Framework 4 when installed on Windows Vista x64 Edition Service Pack 2
Microsoft .NET Framework 4 when installed on Windows Server 2008 for 32-bit Systems Service Pack 2
Microsoft .NET Framework 4 when installed on Windows Server 2008 for x64-based Systems Service Pack 2
Microsoft .NET Framework 4 when installed on Windows 7 for 32-bit Systems
Microsoft .NET Framework 4 when installed on Windows 7 for 32-bit Systems Service Pack 1
Microsoft .NET Framework 4 when installed on Windows 7 for x64-based Systems
Microsoft .NET Framework 4 when installed on Windows 7 for x64-based Systems Service Pack 1
Microsoft .NET Framework 4 when installed on Windows Server 2008 R2 for x64-based Systems
Microsoft .NET Framework 4 when installed on Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 R2 for x64-based Systems
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Microsoft .NET Framework 3.5.1 on Windows Server 2008 R2 for x64-based Systems
Microsoft .NET Framework 3.5.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1
Microsoft .NET Framework 4 when installed on Windows Server 2008 R2 for x64-based Systems Service Pack 1
Microsoft Office 2003 Service Pack 3
Microsoft Office 2007 Service Pack 2
Microsoft Office 2007 Service Pack 3
Microsoft Office 2010 (32-bit editions)
Microsoft Office 2010 Service Pack 1 (32-bit editions)
Microsoft Office 2010 (64-bit editions)
Microsoft Office 2010 Service Pack 1 (64-bit editions)
Microsoft Silverlight 4 when installed on Mac
Microsoft Silverlight 4 when installed on all supported releases of Microsoft Windows clients
Microsoft Silverlight 4 when installed on all supported releases of Microsoft Windows servers
Microsoft Silverlight 5 when installed on Mac
Microsoft Silverlight 5 when installed on all supported releases of Microsoft Windows clients
Microsoft Silverlight 5 when installed on all supported releases of Microsoft Windows servers
Microsoft Lync 2010 (32-bit)
Microsoft Lync 2010 (64-bit)
Microsoft Lync 2010 Attendee

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)