MS11-032: Vulnerability in the OpenType Compact Font Format (CFF) Driver Could Allow Remote Code Execution (2507618)
High Nessus Plugin ID 53389
SynopsisThe remote Windows host contains a font driver that is affected by a privilege escalation vulnerability.
DescriptionThe remote Windows host contains a version of the OpenType Compact Font Format (CFF) Font Driver that improperly parses specially crafted OpenType fonts.
A remote attacker could exploit this by tricking a user into viewing content rendered in a specially crafted CFF font (via vectors such as web, instant message, or email), resulting in arbitrary code execution in kernel mode.
SolutionMicrosoft has released a set of patches for Windows XP, 2003, Vista, 2008, 7, and 2008 R2.