(MS10-078) Vulnerabilities in the OpenType Font (OTF) Format Driver Could Allow Elevation of Privilege (2279986)
Publish Date: 20 Februar 2013
Schweregrad:: Hoch
CVE Kennungen:: CVE-2010-2740,CVE-2010-2741
Hinweisdatum: 20 Februar 2013
Beschreibung
This security update addresses vulnerabilities in the Windows OpenType Font (OTF) format driver that could allow elevation of privilege once a user views content rendered in a specially crafted OpenType font.
This vulnerability could only be exploited when the attacker is log on locally and not remotely.
Trend Micro Lösungen
For information on patches specific to the affected software, please proceed to the Microsoft Web page.
Trend Micro clients using OfficeScan with Intrusion Defense Firewall (IDF) may refer to the table below for the pattern filter identifier(s):
Vulnerability ID | Identifier & Title | IDF First Pattern Version | IDF First Pattern Release Version | ||||
---|---|---|---|---|---|---|---|
CVE-2010-2740 | 1004485 - OpenType Font Parsing Vulnerability | 10-035 | Nov 09, 2010 |
Lösungen
Betroffene Software und Version:
- Windows Server 2003 Service Pack 2
- Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Server 2003 x64 Edition Service Pack 2
- Windows XP Professional x64 Edition Service Pack 2
- Windows XP Service Pack 3