Win32k TrueType font-parsing engine vulnerability


Microsoft issued an advisory this week on the TrueType font-parsing vulnerability. The flaw affects every supported version of Windows including Windows 7 and Windows Server 2008. The vulnerability was found to spread the Duqu malware, which is derived from the infamous Stuxnet worm. Microsoft say that an attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. Access to kernel mode means an attacker could install programs, view, change, or delete data; or create new accounts with full user rights. Microsoft will be patching this Windows 7 vulnerability on November Patch Tuesday.

November 4, 2011
Notify of

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Inline Feedbacks
View all comments
© HAKIN9 MEDIA SP. Z O.O. SP. K. 2023