Microsoft Windows Open Type Font Remote Code Execution Vulnerability
Microsoft · Windows
Date added (CISA)
2022-05-25
Remediation due
2022-06-15
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerability could take control of the affected system.