CVE Vulnerabilities

CVE-2018-8332

Published: Sep 13, 2018 | Modified: Oct 03, 2019
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka Win32k Graphics Remote Code Execution Vulnerability. This affects Windows 7, Microsoft Office, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.

Affected Software

Name Vendor Start Version End Version
Office Microsoft 2016 (including) 2016 (including)
Office_for_mac Microsoft 2016 (including) 2016 (including)
Windows_10 Microsoft - (including) - (including)
Windows_10 Microsoft 1607 (including) 1607 (including)
Windows_10 Microsoft 1703 (including) 1703 (including)
Windows_10 Microsoft 1709 (including) 1709 (including)
Windows_10 Microsoft 1803 (including) 1803 (including)
Windows_7 Microsoft –sp1 (including) –sp1 (including)
Windows_8.1 Microsoft - (including) - (including)
Windows_server Microsoft 2008-r2 (including) 2008-r2 (including)
Windows_server Microsoft 2008-sp2 (including) 2008-sp2 (including)
Windows_server Microsoft 2012 (including) 2012 (including)
Windows_server Microsoft 2012-r2 (including) 2012-r2 (including)
Windows_server Microsoft 2016 (including) 2016 (including)
Windows_server Microsoft 2016-1709 (including) 2016-1709 (including)
Windows_server Microsoft 2016-1803 (including) 2016-1803 (including)

References