vendor:
Windows 8.1
by:
Google Security Research
7,2
CVSS
HIGH
Windows Kernel Memory Corruption
119
CWE
Product Name: Windows 8.1
Affected Version From: Windows Vista
Affected Version To: Windows 8.1
Patch Exists: YES
Related CWE: CVE-2013-3128
CPE: o:microsoft:windows_8.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2013
Windows Kernel Memory Corruption
A vulnerability in the Windows kernel's ATMFD.DLL OpenType driver allows for a denial of service attack when processing corrupted OTF font files. The vulnerability is triggered when the driver attempts to access memory that has already been freed, resulting in a DRIVER_PAGE_FAULT_IN_FREED_SPECIAL_POOL (d5) bugcheck.
Mitigation:
Microsoft released a patch to address this vulnerability.