HTTP: Microsoft Windows EOT Font Engine Information Disclosure

This signature detects attempt to exploit an information disclosure vulnerability which has been reported in the EOT component of Microsoft Windows operating systems. A remote attacker could exploit this vulnerability by enticing a user to open specially crafted document. Successful exploitation could result in information disclosure which could be used to further compromise the target system.

Extended Description

The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1 and Windows Server 2008 R2 allows information disclosure, due to how the Windows EOT font engine handles embedded fonts, aka "Windows EOT Font Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0755, CVE-2018-0760, and CVE-2018-0855.

Affected Products

Microsoft windows_7

References

BugTraq: 102952

CVE: CVE-2018-0761

Short Name
HTTP:STC:MS-EOT-FONT-ENGINE-ID1
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2018-0761 Disclosure EOT Engine Font Information Microsoft Windows bid:102952
Release Date
04/03/2018
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Unknown
Vendors

Microsoft

CVSS Score

2.1

Found a potential security threat?