This application requires Javascript for optimal performance.

MS.Windows.ATMFD.Font.Driver.Remote.Code.Execution

Release Date

Jun 15, 2011

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attempt to exploit an remote Code Execution vulnerability in Microsoft Windows ATMFD font driver.

The vulnerability is caused by an error when the vulnerable software handles
a crafted font file. It may allow remote attackers to execute arbitrary code on vulnerable systems.

Affected Products

Windows XP Professional x64 Edition Service Pack 2
Windows Server 2003 x64 Edition Service Pack 2
Windows Server 2003 with SP2 for Itanium-based Systems
Windows Vista x64 Edition Service Pack 1 and Windows Vista x64 Edition Service Pack 2
Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for Itanium-based Systems and Windows Server 2008 for Itanium-based Systems Service Pack 2
Windows 7 for x64-based Systems and Windows 7 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for Itanium-based Systems and Windows Server 2008 R2 for Itanium-based Systems Service Pack 1

Recommended Actions

Apply the patch, available from the vendor's website:
http://www.microsoft.com/technet/security/Bulletin/MS11-041.mspx

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-1873

Reference/s

http://technet.microsoft.com/en-us/security/bulletin/MS11-041.mspx (MS-ID)

Reference: VID-27651