imPC@ndo IT

Tracker / CVE-2012-2897

CVE-2012-2897

High 7.8

The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT, as used by Google Chrome before 22.0.1229.79 and other programs, do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a crafted TrueType font file, aka "Windows Font Parsing Vulnerability" or "TrueType Font Parsing Vulnerability."

Affected products and versions

google chrome
google chrome · … → 22.0.1229.78
microsoft windows_7
microsoft windows_8
microsoft windows_rt
microsoft windows_server_2003
microsoft windows_server_2008
microsoft windows_server_2012
microsoft windows_vista
microsoft windows_xp

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References