Microsoft Windows Remote Code Execution Vulnerability
Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 및 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold 및 R2, Windows RT Gold 및 8.1의 커널 모드 드라이버에 있는 win32k.sys에서는 원격 공격자가 조작된 TrueType 글꼴을 통해 임의 코드를 실행할 수 있으며, 이는 2014년 10월 실제로 악용되었습니다. 이 취약점은 "TrueType Font Parsing Remote Code Execution Vulnerability"라고도 합니다.
Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 및 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold 및 R2, Windows RT Gold 및 8.1의 커널 모드 드라이버에 있는 win32k.sys에서는 원격 공격자가 조작된 TrueType 글꼴을 통해 임의 코드를 실행할 수 있으며, 이는 2014년 10월 실제로 악용되었습니다. 이 취약점은 "TrueType Font Parsing Remote Code Execution Vulnerability"라고도 합니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted TrueType font, as exploited in the wild in October 2014, aka "TrueType Font Parsing Remote Code Execution Vulnerability."