HTTP: Microsoft Windows OpenType Font (OTF) Font Size Table

This signature detects attempts to exploit a known vulnerability against theOpenType Font (OTF) driver included in Windows.A remote code execution vulnerability exists in the way that the OpenType Font (OTF) driver improperly parses specially crafted OpenType fonts. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

Extended Description

Microsoft Windows is prone to a remote code-execution vulnerability that affects the OpenType Font (OTF) driver. An attacker can exploit this issue to execute arbitrary code in kernel mode. Successful exploits will completely compromise an affected computer. Failed attempts will result in a denial-of-service condition.

Affected Products

Avaya messaging_application_server,Microsoft windows_xp

References

BugTraq: 45316

CVE: CVE-2010-3959

Short Name
HTTP:STC:DL:OTF-FONT-SIZE
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
(OTF) CVE-2010-3959 Font Microsoft OpenType Size Table Windows bid:45316
Release Date
12/13/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3339
False Positive
Unknown
Vendors

Microsoft

Avaya

CVSS Score

6.9

Found a potential security threat?