Microsoft Windows EOT Font Engine Information Disclosure (CVE-2018-0755)

An information disclosure vulnerability has been reported in the EOT component of Microsoft Windows operating systems. The vulnerability is due to improper handling of objects in the Windows EOT Font Engine. A remote attacker could exploit this vulnerability by enticing a user to open specially crafted document, successful exploitation could result in information disclosure which could be used to further compromise the target system.

from Check Point Update Services Advisories http://ift.tt/2FdfLQT

No comments:

Post a Comment

Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading

Cybersecurity researchers have uncovered a new phishing campaign that exploits social media private messages to propagate malicious payloads...