| Microsoft Windows Knowledge Base Article 972270 update is not installed (WinMs10kb972270Update) |
|---|
| Vuln ID: | 55150 | |
|---|---|---|
| Risk Level: | High |
WinMs10kb972270Update |
| Platforms: | Microsoft Windows 2000: SP4, Microsoft Windows XP: SP2, Microsoft Windows Vista, Microsoft Windows Server 2003: SP2, Microsoft Windows Server 2003: SP2 Itanium, Microsoft Windows Server 2003: SP2 x64, Microsoft Windows Vista: x64, Microsoft Windows XP: SP2 x64 Professional, Microsoft Windows Vista: SP1, Microsoft Windows Vista: SP1 x64, Microsoft Windows Server 2008: Itanium, Microsoft Windows Server 2008: x32, Microsoft Windows Server 2008: x64, Microsoft Windows XP: SP3, Microsoft Windows Vista: SP2 x64, Microsoft Windows Vista: SP2, Microsoft Windows Server 2008: SP2 x32, Microsoft Windows Server 2008: SP2 x64, Microsoft Windows 7: x64, Microsoft Windows 7: x32, Microsoft Windows Server 2008: R2 x64, Microsoft Windows Server 2008: R2 Itanium, Microsoft Windows Server 2008: SP2 Itanium | |
| Description: | Microsoft Windows Knowledge Base Article 972270 update is not installed on the system, which could allow an attacker to exploit the following vulnerability: Microsoft Windows is vulnerable to a heap-based buffer overflow, caused by an integer overflow when the Embedded OpenType Font Engine decompresses malicious files. By persuading a victim to open a specially-crafted file containing EOT font embedded in the document, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash. |
|
| Remedy: | Apply the appropriate patch for your system, as listed in Microsoft Security Bulletin MS10-001. See References. |
|
| False Positives: | ||
| False Negatives: | ||
| Required Permission: | Windows login | |
| Additional Information: | ||
| References: | IBM Internet Security Systems X-Force Database Microsoft Security Bulletin MS10-001 ISS X-Force CVE CVE-2010-0018 |
|
![]() Know Your Risks |
![]() Common Vulnerabilties & Exposures |