CVE Database
/

CVE-2018-8332

Back to search

CVE-2018-8332

Published: Sep 13, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability." This affects Windows 7, Microsoft Office, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.

VendorProductVersions

Microsoft

Windows 7

affected
32-bit Systems Service Pack 1
affected
x64-based Systems Service Pack 1

Microsoft

Microsoft Office

affected
2016 Click-to-Run (C2R) for 32-bit editions
affected
2016 Click-to-Run (C2R) for 64-bit editions
affected
2016 for Mac

Microsoft

Windows Server 2012 R2

affected
(Server Core installation)

Microsoft

Windows RT 8.1

affected
Windows RT 8.1

Microsoft

Windows Server 2008

affected
32-bit Systems Service Pack 2
affected
32-bit Systems Service Pack 2 (Server Core installation)
affected
Itanium-Based Systems Service Pack 2
affected
x64-based Systems Service Pack 2
affected
x64-based Systems Service Pack 2 (Server Core installation)

Microsoft

Windows Server 2008 R2

affected
Itanium-Based Systems Service Pack 1
affected
x64-based Systems Service Pack 1
affected
x64-based Systems Service Pack 1 (Server Core installation)

Microsoft

Windows Server 2012

affected
(Server Core installation)

Microsoft

Windows Server 2016

affected
(Server Core installation)

Microsoft

Windows 8.1

affected
32-bit systems
affected
x64-based systems

Microsoft

Windows 10

affected
32-bit Systems
affected
Version 1607 for 32-bit Systems
affected
Version 1607 for x64-based Systems
affected
Version 1703 for 32-bit Systems
affected
Version 1703 for x64-based Systems

+5 more versions

Microsoft

Windows 10 Servers

affected
version 1709 (Server Core Installation)
affected
version 1803 (Server Core Installation)

References

105248
vdb-entry
x_refsource_BID
1041628
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now