#VU22710 Input validation error in Windows and Windows Server


Published: 2019-11-12

Vulnerability identifier: #VU22710

Vulnerability risk: High

CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2019-1456

CWE-ID: CWE-20

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Windows
Operating systems & Components / Operating system
Windows Server
Operating systems & Components / Operating system

Vendor: Microsoft

Description

The vulnerability allows a local attacker to execute arbitrary code on the target system.

The vulnerability exists due to the way Windows Adobe Type Manager Library handles specially crafted OpenType fonts. A remote attacker can create a specially crafted web page or document with embedded malicious font, trick the victim into opening it and execute arbitrary code on the system with privileges of the current user.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Windows: 7, 8.1 - 8.1 RT, 10 1607 10.0.14393.10, 10 1709 10.0.16299.19, 10 1803 10.0.17134.48, 10 1809 10.0.17763.1, 10 1903 10.0.18362.116

Windows Server: 2008 - 2019 1903


External links
http://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1456


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability