Improper input validation in Windows and Windows Server - CVE-2017-11762
Published: October 10, 2017
Vulnerability identifier: #VU8725
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2017-11762
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Microsoft
Affected software:
Windows
Windows Server
Windows
Windows Server
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists due to improper handling of specially crafted embedded fonts by the Windows font library. A remote attacker can send a specially crafted content, trick the victim into opening it and execute arbitrary code with SYSTEM privileges.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists due to improper handling of specially crafted embedded fonts by the Windows font library. A remote attacker can send a specially crafted content, trick the victim into opening it and execute arbitrary code with SYSTEM privileges.
Successful exploitation of the vulnerability may result in system compromise.
How to mitigate CVE-2017-11762
Install update from vendor's website.