MS11-007: Vulnerability in the OpenType Compact Font Format (CFF) Driver Could Allow Remote Code Execution (2485376)
High Nessus Plugin ID 51907
SynopsisThe remote Windows host contains a font driver that is affected by a privilege escalation vulnerability.
DescriptionThe remote Windows host contains a version of the OpenType Compact Font Format (CFF) Font Driver that fails to properly validate certain data passed from user mode to kernel mode.
A remote attacker could exploit this by tricking a user into viewing content rendered in a specially crafted CFF font (via vectors such as web, instant message, or email), resulting in arbitrary code execution in kernel mode.
SolutionMicrosoft has released a set of patches for Windows XP, 2003, Vista, 2008, 7, and 2008 R2.