Executive brief
A remote code execution vulnerability exists in the Windows kernel-mode driver (win32k.sys) due to improper handling of TrueType fonts. An attacker can exploit this by convincing a user to open a specially crafted font file, leading to arbitrary code execution.
Affected products
- Microsoft Windows Server 2003 SP2
- Microsoft Windows Vista SP2
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft Windows 7 SP1
- Microsoft Windows 8
- Microsoft Windows 8.1
- Microsoft Windows Server 2012 Gold, R2
- Microsoft Windows RT Gold, 8.1
Timeline
- 2014-10-14: exploited: Exploited in the wild in October 2014.
- 2014-10-14: patched: Microsoft released security bulletin MS14-058.
- 2022-05-25: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.