Description
OpenType Font Parsing Remote Code Execution Vulnerability
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
E
Unchanged
RL
O
RC
Changed
Affected products
- microsoft / Windows 1020h2 – 20h2
- microsoft / Windows 102004 – 2004
- microsoft / Windows 101909 – 1909
- microsoft / Windows 101809 – 1809
- microsoft / Windows 101803 – 1803
- microsoft / windows_10_1803
- microsoft / windows_10_1803
- microsoft / windows_10_1809
- microsoft / windows_10_1809
- microsoft / windows_10_1809
- microsoft / windows_10_1909
- microsoft / windows_10_1909
- microsoft / windows_10_20H2
- microsoft / windows_10_20H2
- microsoft / Windows 10 Version 180310.0.0 – 10.0.17134.2087
- microsoft / Windows 10 Version 180910.0.0 – 10.0.17763.1817
- microsoft / Windows 10 Version 180910.0.17763.0 – 10.0.17763.1817
- microsoft / Windows 10 Version 190910.0.0 – 10.0.18363.1440
- microsoft / Windows 10 Version 200410.0.0 – 10.0.19043.867
- microsoft / Windows 10 Version 20H210.0.0 – 10.0.19043.867
- microsoft / windows_server_1909
- microsoft / windows_server_2004
- microsoft / Windows Server 20162019 – 2019
- microsoft / Windows Server 201620h2 – 20h2
- microsoft / Windows Server 20161909 – 1909
- microsoft / Windows Server 20162004 – 2004
- microsoft / Windows Server 201910.0.17763.0 – 10.0.17763.1817
- microsoft / Windows Server 2019
- microsoft / Windows Server 2019 (Server Core installation)10.0.17763.0 – 10.0.17763.1817
- microsoft / windows_server_20H2
- microsoft / Windows Server, version 1909 (Server Core installation)10.0.0 – 10.0.18363.1440
- microsoft / Windows Server version 200410.0.0 – 10.0.19043.867
- microsoft / Windows Server version 20H210.0.0 – 10.0.19043.867
References
Updated 7m ago · 8 sources