header-logo
Suggest Exploit
vendor:
N/A
by:
Google Security Research
7,8
CVSS
HIGH
Out-of-bounds Read
125
CWE
Product Name: N/A
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2014

Windows Kernel Crash in ATMFD.DLL OpenType Driver

A Windows kernel crash was encountered in the ATMFD.DLL OpenType driver while processing corrupted OTF font files. The crash was caused by an out-of-bounds read in the ATMFD+2a902 address. The crash was triggered when more than N bytes were being referenced, which cannot be protected by try-except.

Mitigation:

Ensure that all font files are validated before being processed.
Source

Exploit-DB raw data: