HTTP: Microsoft Windows OpenType Compact Font Format Driver Code Execution

This signature detects attempts to exploit a known vulnerability against Microsoft Windows OpenType. A code execution vulnerability exists in Microsoft Windows OpenType Compact Font Format (CFF) Driver. The vulnerability is due to the OpenType Compact Font Format (CFF) Driver not sufficiently validating the parameter values of specially crafted OpenType fonts.

Extended Description

Microsoft Windows is prone to a remote code-execution vulnerability that affects the OpenType Compact Font Format (CFF) driver. An attacker can exploit this issue to execute arbitrary code in kernel mode. Successful exploits will completely compromise an affected computer. Failed attempts will result in a denial-of-service condition.

Affected Products

Avaya messaging_application_server,Microsoft windows_xp

References

BugTraq: 46106

CVE: CVE-2011-0033

Short Name
HTTP:STC:DL:OTF-CFF-RCE
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2011-0033 Code Compact Driver Execution Font Format Microsoft OpenType Windows bid:46106
Release Date
02/08/2011
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3339
False Positive
Unknown
Vendors

Microsoft

Avaya

CVSS Score

9.3

Found a potential security threat?