A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Win32k Graphics Remote Code Execution Vulnerability'.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1468 | patch vendor advisory |
https://www.zerodayinitiative.com/advisories/ZDI-19-1004/ | third party advisory |