Out-of-bounds read in Microsoft Windows and Windows Server - CVE-2018-0754
Published: January 3, 2018 / Updated: January 4, 2018
Vulnerability identifier: #VU9847
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0754
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to an out-of-bounds read error in Windows Adobe Type Manager Font Driver (ATMFD.dll). A local user can run a specially crafted application to trigger memory corruption and gain access to information that could be used to try to further compromise the affected system.
The vulnerability exists due to an out-of-bounds read error in Windows Adobe Type Manager Font Driver (ATMFD.dll). A local user can run a specially crafted application to trigger memory corruption and gain access to information that could be used to try to further compromise the affected system.
Affected software
Microsoft Windows
Windows Server
Windows Server
How to mitigate CVE-2018-0754
Install updates from vendor's website.