#VU22710 Input validation error in Windows and Windows Server - CVE-2019-1456
Published: November 12, 2019
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local attacker to execute arbitrary code on the target system.
The vulnerability exists due to the way Windows Adobe Type Manager Library handles specially crafted OpenType fonts. A remote attacker can create a specially crafted web page or document with embedded malicious font, trick the victim into opening it and execute arbitrary code on the system with privileges of the current user.