ms10-001: vulnerability in the embedded opentype font engine could allow remote code execution for Windows Vista (KB972270) x86 based systems for SP1

Risk Information

Base Score
8.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
68.946%

CVE Information

Source CVE
CVE-2010-0018

Associated CVE
CVE-2010-0018

Patch Details

No records found

References

http://blogs.technet.com/srd/archive/2010/01/12/ms10-001-font-file-decompression-vulnerability.aspx
http://osvdb.org/61651
http://secunia.com/advisories/35457
http://www.microsoft.com/technet/security/Bulletin/MS10-001.mspx
http://www.securityfocus.com/bid/37671
http://www.securitytracker.com/id?1023432
http://www.us-cert.gov/cas/techalerts/TA10-012B.html
http://www.vupen.com/english/advisories/2010/0095