vendor:
Microsoft Unicode Scripts Processor
by:
Shahin and info from Abysssec
9,3
CVSS
CRITICAL
Remote Code Execution
119
CWE
Product Name: Microsoft Unicode Scripts Processor
Affected Version From: Microsoft Windows XP and Vista
Affected Version To: Microsoft Windows XP and Vista
Patch Exists: YES
Related CWE: CVE-2010-2738
CPE: o:microsoft:windows_xp::sp3,cpe:/o:microsoft:windows_vista::sp2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP and Vista
2010
Microsoft Unicode Scripts Processor Remote Code Execution
A vulnerability exists in Microsoft Unicode Scripts Processor (usp10.dll) which allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows XP and Vista. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of font files. The vulnerability is due to a lack of bounds checking when parsing a specially crafted font file. An attacker can leverage this vulnerability to execute code in the context of the current process.
Mitigation:
Microsoft has released a patch to address this vulnerability.