SB2018041038 - Privilege escalation in OpenType font driver in Microsoft Windows
Published: April 10, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2018-1008)
The vulnerability allows a local user to elevate privileges on the system.
The vulnerability exists due to boundary error in Windows Adobe Type Manager Font Driver (ATMFD.dll). A local user can run a specially crafted application to trigger memory corruption and execute arbitrary code on the target system with elevated privileges.
Remediation
Install update from vendor's website.