Out-of-bounds read in Microsoft Windows and Windows Server - CVE-2018-0754

 

Out-of-bounds read in Microsoft Windows and Windows Server - CVE-2018-0754

Published: January 3, 2018 / Updated: January 4, 2018


Vulnerability identifier: #VU9847
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0754
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to an out-of-bounds read error in Windows Adobe Type Manager Font Driver (ATMFD.dll). A local user can run a specially crafted application to trigger memory corruption and gain access to information that could be used to try to further compromise the affected system.


Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2018-0754

Install updates from vendor's website.


External References

Related Security Bulletins