MS11-007: Vulnerability in the OpenType Compact Font Format (CFF) Driver Could Allow Remote Code Execution (2485376)
High Nessus Plugin ID 51907
SynopsisThe remote Windows host contains a font driver that is affected by a
privilege escalation vulnerability.
DescriptionThe remote Windows host contains a version of the OpenType Compact
Font Format (CFF) Font Driver that fails to properly validate certain
data passed from user mode to kernel mode.
A remote attacker could exploit this by tricking a user into viewing
content rendered in a specially crafted CFF font (via vectors such as
web, instant message, or email), resulting in arbitrary code execution
in kernel mode.
SolutionMicrosoft has released a set of patches for Windows XP, 2003, Vista,
2008, 7, and 2008 R2.