Hackers about hacking techniques in our IT Security Magazine

Win32k TrueType font-parsing engine vulnerability

Microsoft issued an advisory this week on the TrueType font-parsing vulnerability. The flaw affects every supported version of Windows including Windows 7 and Windows Server 2008. The vulnerability was found to spread the Duqu malware, which is derived from the infamous Stuxnet worm. Microsoft say that an attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. Access to kernel mode means an attacker could install programs, view, change, or delete data; or create new accounts with full user rights. Microsoft will be patching this Windows 7 vulnerability on November Patch Tuesday.

November 4, 2011

0 Responses on Win32k TrueType font-parsing engine vulnerability"

Leave a Message

Your email address will not be published.

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>