CVE-2018-1008
published 2018-04-12CVE-2018-1008: An elevation of privilege vulnerability exists in Windows Adobe Type Manager Font Driver (ATMFD.dll) when it fails to properly handle objects in memory, aka…
PriorityP430high7CVSS 3.0
AVLACHPRLUINSUCHIHAH
EPSS
1.15%
63.4th percentile
An elevation of privilege vulnerability exists in Windows Adobe Type Manager Font Driver (ATMFD.dll) when it fails to properly handle objects in memory, aka "OpenType Font Driver Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_servers | — | — |
| microsoft | windows_7 | — | — |
| microsoft | windows_7 | — | — |
| microsoft | windows_8.1 | — | — |
| microsoft | windows_8.1 | — | — |
| microsoft | windows_rt_8.1 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
CVSS provenance
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2x59-22p6-6v87: An elevation of privilege vulnerability exists in Windows Adobe Type Manager Font Driver (ATMFD
ghsa_unreviewed·2022-05-13
CVE-2018-1008 [HIGH] GHSA-2x59-22p6-6v87: An elevation of privilege vulnerability exists in Windows Adobe Type Manager Font Driver (ATMFD
An elevation of privilege vulnerability exists in Windows Adobe Type Manager Font Driver (ATMFD.dll) when it fails to properly handle objects in memory, aka "OpenType Font Driver Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Microsoft
Graphics Component Font Parsing Elevation of Privilege Vulnerability
vendor_msrc·2018-04-10·CVSS 7.0
CVE-2018-1008 [HIGH] Graphics Component Font Parsing Elevation of Privilege Vulnerability
Graphics Component Font Parsing Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploits this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.
The update addresses the vulnerability by correcting the way in which the Windows Graphics Component handles objects in memory, preventing unintended
No detection rules found.
No public exploits indexed.
Trendmicro
Microsoft Fixes Vulnerabilities in Fonts and Keyboard
blogs_trendmicro·2018-04-11·CVSS 5.3
[MEDIUM] Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Exploits & Vulnerabilities
## Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Microsof's Patch Tuesday for April addressed security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine.
By: IoT Reputation Service Team 2018/04/11 Read time: ( words)
Save to Folio
Microsoft has rolled out its Patch Tuesday for April to address security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine. Of the 67 listed vulnerabilities, 24 were rated critical. Eight of these were disclosed through Trend Micro’s ZDI program:
CVE-2018-1011
CVE-2018-1008
CVE-2018-1004
CVE-2018-1001
CVE-2018-1000
CVE-2018-0
Trendmicro
Microsoft Fixes Vulnerabilities in Fonts and Keyboard
blogs_trendmicro·2018-04-11·CVSS 5.3
[MEDIUM] Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Exploits & Vulnerabilities
# Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Microsof's Patch Tuesday for April addressed security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine.
By: IoT Reputation Service Team
2018/04/11
Read time: ( words)
Save to Folio
Microsoft has rolled out its Patch Tuesday for April to address security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine. Of the 67 listed vulnerabilities, 24 were rated critical. Eight of these were disclosed through Trend Micro’s ZDI program:
- CVE-2018-1011
- CVE-2018-1008
- CVE-2018-1004
- CVE-2018-1001
- CVE-2018-1000
- CVE
Trendmicro
Microsoft Fixes Vulnerabilities in Fonts and Keyboard
blogs_trendmicro·2018-04-11·CVSS 5.3
[MEDIUM] Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Exploits & Vulnerabilities
## Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Microsof's Patch Tuesday for April addressed security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine.
By: IoT Reputation Service Team Apr 11, 2018 Read time: ( words)
Save to Folio
Microsoft has rolled out its Patch Tuesday for April to address security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine. Of the 67 listed vulnerabilities, 24 were rated critical. Eight of these were disclosed through Trend Micro’s ZDI program:
CVE-2018-1011
CVE-2018-1008
CVE-2018-1004
CVE-2018-1001
CVE-2018-1000
CVE-2018
Trendmicro
Microsoft Fixes Vulnerabilities in Fonts and Keyboard
blogs_trendmicro·2018-04-11·CVSS 5.3
[MEDIUM] Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Ausnutzung von Schwachstellen
## Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Microsof's Patch Tuesday for April addressed security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine.
By: IoT Reputation Service Team Apr 11, 2018 Read time: ( words)
Save to Folio
Microsoft has rolled out its Patch Tuesday for April to address security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine. Of the 67 listed vulnerabilities, 24 were rated critical. Eight of these were disclosed through Trend Micro’s ZDI program:
CVE-2018-1011
CVE-2018-1008
CVE-2018-1004
CVE-2018-1001
CVE-2018-1000
CVE-2
Trendmicro
Microsoft Fixes Vulnerabilities in Fonts and Keyboard
blogs_trendmicro·2018-04-11·CVSS 5.3
[MEDIUM] Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Exploits y vulnerabilidades
## Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Microsof's Patch Tuesday for April addressed security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine.
By: IoT Reputation Service Team Apr 11, 2018 Read time: ( words)
Save to Folio
Microsoft has rolled out its Patch Tuesday for April to address security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine. Of the 67 listed vulnerabilities, 24 were rated critical. Eight of these were disclosed through Trend Micro’s ZDI program:
CVE-2018-1011
CVE-2018-1008
CVE-2018-1004
CVE-2018-1001
CVE-2018-1000
CVE-201
Talos
Microsoft Patch Tuesday - April 2018
blogs_talos·2018-04-10·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - April 2018
## Microsoft Patch Tuesday - April 2018
## Microsoft Patch Tuesday - April 2018 Today, Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 65 new vulnerabilities and one advisory, with 25 of them rated critical, 39 of them rated important and one of them rated moderate. These vulnerabilities impact Microsoft Windows, Internet Explorer, Microsoft Edge, Microsoft Office, Windows kernel, Windows Hyper-V, Microsoft Scripting Engine and more.
In addition, an update for Adobe Flash Player was released.
## Critical Vulnerabilities This month, Microsoft is addressing 25 vulnerabilities that are rated "critical".
The vulnerabilities rated as "critical" are listed be
Talos
Microsoft Patch Tuesday - April 2018
blogs_talos·2018-04-10·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - April 2018
## Microsoft Patch Tuesday - April 2018Today, Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 65 new vulnerabilities and one advisory, with 25 of them rated critical, 39 of them rated important and one of them rated moderate. These vulnerabilities impact Microsoft Windows, Internet Explorer, Microsoft Edge, Microsoft Office, Windows kernel, Windows Hyper-V, Microsoft Scripting Engine and more.
In addition, an update for Adobe Flash Player was released.
### Critical VulnerabilitiesThis month, Microsoft is addressing 25 vulnerabilities that are rated "critical".
The vulnerabilities rated as "critical" are listed below:
CVE-2018-0870 - Internet Explorer Me
http://www.securityfocus.com/bid/103658http://www.securitytracker.com/id/1040673https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-1008http://www.securityfocus.com/bid/103658http://www.securitytracker.com/id/1040673https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-1008
2018-04-12
Published