CVE-2018-1016
published 2018-04-12CVE-2018-1016: A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote…
PriorityP259high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
23.49%
97.5th percentile
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-1010, CVE-2018-1012, CVE-2018-1013, CVE-2018-1015.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2016 | — | — |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1511 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1703 | — | — |
| msrc | windows_10_version_1709 | — | — |
| msrc | windows_7 | — | — |
| msrc | windows_8.1 | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2008 | — | — |
| msrc | windows_server_2008_r2 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_version_1709 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Attack vector: web-based delivery via specially crafted website hosting malicious embedded fonts — monitor for suspicious font file downloads or rendering in browser contexts ↗
- →Attack vector: file-sharing / email attachment delivery via specially crafted document files containing embedded fonts — inspect Office/PDF documents for anomalous embedded font data ↗
- →Vulnerable component is the Windows font library (ATMFD / win32k font parsing); focus detection on processes that parse embedded fonts (e.g., winword.exe, iexplore.exe, msedge.exe, chrome.exe) triggering anomalous kernel or graphics subsystem calls ↗
- →Exploitation assessed 'More Likely' for both latest and older software releases — prioritise alerting on unpatched Windows systems (Windows 7, 8.1, 10, Server 2008/2012/2016) processing untrusted font content ↗
- ·No public exploit or active in-the-wild exploitation confirmed at time of advisory publication ↗
- ·CVE-2018-1016 is one of five related Microsoft Graphics font-handling RCE CVEs patched simultaneously; ensure detections distinguish it from CVE-2018-1010, CVE-2018-1012, CVE-2018-1013, and CVE-2018-1015 ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Graphics Remote Code Execution Vulnerability
vendor_msrc·2018-04-10·CVSS 8.8
CVE-2018-1016 [HIGH] Microsoft Graphics Remote Code Execution Vulnerability
Microsoft Graphics Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
There are multiple ways an attacker could exploit the vulnerability:
In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability and then convince users to view
GHSA
GHSA-cjm3-fphr-cx5c: A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphic
ghsa_unreviewed·2022-05-13·CVSS 8.8
CVE-2018-1016 [HIGH] CWE-20 GHSA-cjm3-fphr-cx5c: A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphic
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-1010, CVE-2018-1012, CVE-2018-1013, CVE-2018-1015.
GHSA
GHSA-8378-j23v-vjwx: A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphic
ghsa_unreviewed·2022-05-13·CVSS 8.8
CVE-2018-1015 [HIGH] CWE-20 GHSA-8378-j23v-vjwx: A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphic
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-1010, CVE-2018-1012, CVE-2018-1013, CVE-2018-1016.
GHSA
GHSA-cfvg-53wh-32hr: A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphic
ghsa_unreviewed·2022-05-13·CVSS 8.8
CVE-2018-1013 [HIGH] CWE-20 GHSA-cfvg-53wh-32hr: A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphic
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-1010, CVE-2018-1012, CVE-2018-1015, CVE-2018-1016.
GHSA
GHSA-5mfr-27pq-2pg7: A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphic
ghsa_unreviewed·2022-05-13·CVSS 8.8
CVE-2018-1010 [HIGH] CWE-20 GHSA-5mfr-27pq-2pg7: A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphic
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-1012, CVE-2018-1013, CVE-2018-1015, CVE-2018-1016.
GHSA
GHSA-4ph8-r85v-ggp6: A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphic
ghsa_unreviewed·2022-05-13·CVSS 8.8
CVE-2018-1012 [HIGH] CWE-20 GHSA-4ph8-r85v-ggp6: A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphic
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-1010, CVE-2018-1013, CVE-2018-1015, CVE-2018-1016.
No detection rules found.
No public exploits indexed.
Trendmicro
Microsoft Fixes Vulnerabilities in Fonts and Keyboard
blogs_trendmicro·2018-04-11·CVSS 5.3
[MEDIUM] Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Exploits & Vulnerabilities
## Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Microsof's Patch Tuesday for April addressed security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine.
By: IoT Reputation Service Team 2018/04/11 Read time: ( words)
Save to Folio
Microsoft has rolled out its Patch Tuesday for April to address security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine. Of the 67 listed vulnerabilities, 24 were rated critical. Eight of these were disclosed through Trend Micro’s ZDI program:
CVE-2018-1011
CVE-2018-1008
CVE-2018-1004
CVE-2018-1001
CVE-2018-1000
CVE-2018-0
Trendmicro
Microsoft Fixes Vulnerabilities in Fonts and Keyboard
blogs_trendmicro·2018-04-11·CVSS 5.3
[MEDIUM] Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Exploits & Vulnerabilities
# Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Microsof's Patch Tuesday for April addressed security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine.
By: IoT Reputation Service Team
2018/04/11
Read time: ( words)
Save to Folio
Microsoft has rolled out its Patch Tuesday for April to address security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine. Of the 67 listed vulnerabilities, 24 were rated critical. Eight of these were disclosed through Trend Micro’s ZDI program:
- CVE-2018-1011
- CVE-2018-1008
- CVE-2018-1004
- CVE-2018-1001
- CVE-2018-1000
- CVE
Trendmicro
Microsoft Fixes Vulnerabilities in Fonts and Keyboard
blogs_trendmicro·2018-04-11·CVSS 5.3
[MEDIUM] Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Exploits & Vulnerabilities
## Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Microsof's Patch Tuesday for April addressed security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine.
By: IoT Reputation Service Team Apr 11, 2018 Read time: ( words)
Save to Folio
Microsoft has rolled out its Patch Tuesday for April to address security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine. Of the 67 listed vulnerabilities, 24 were rated critical. Eight of these were disclosed through Trend Micro’s ZDI program:
CVE-2018-1011
CVE-2018-1008
CVE-2018-1004
CVE-2018-1001
CVE-2018-1000
CVE-2018
Trendmicro
Microsoft Fixes Vulnerabilities in Fonts and Keyboard
blogs_trendmicro·2018-04-11·CVSS 5.3
[MEDIUM] Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Ausnutzung von Schwachstellen
## Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Microsof's Patch Tuesday for April addressed security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine.
By: IoT Reputation Service Team Apr 11, 2018 Read time: ( words)
Save to Folio
Microsoft has rolled out its Patch Tuesday for April to address security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine. Of the 67 listed vulnerabilities, 24 were rated critical. Eight of these were disclosed through Trend Micro’s ZDI program:
CVE-2018-1011
CVE-2018-1008
CVE-2018-1004
CVE-2018-1001
CVE-2018-1000
CVE-2
Trendmicro
Microsoft Fixes Vulnerabilities in Fonts and Keyboard
blogs_trendmicro·2018-04-11·CVSS 5.3
[MEDIUM] Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Exploits y vulnerabilidades
## Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Microsof's Patch Tuesday for April addressed security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine.
By: IoT Reputation Service Team Apr 11, 2018 Read time: ( words)
Save to Folio
Microsoft has rolled out its Patch Tuesday for April to address security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine. Of the 67 listed vulnerabilities, 24 were rated critical. Eight of these were disclosed through Trend Micro’s ZDI program:
CVE-2018-1011
CVE-2018-1008
CVE-2018-1004
CVE-2018-1001
CVE-2018-1000
CVE-201
Talos
Microsoft Patch Tuesday - April 2018
blogs_talos·2018-04-10·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - April 2018
## Microsoft Patch Tuesday - April 2018
## Microsoft Patch Tuesday - April 2018 Today, Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 65 new vulnerabilities and one advisory, with 25 of them rated critical, 39 of them rated important and one of them rated moderate. These vulnerabilities impact Microsoft Windows, Internet Explorer, Microsoft Edge, Microsoft Office, Windows kernel, Windows Hyper-V, Microsoft Scripting Engine and more.
In addition, an update for Adobe Flash Player was released.
## Critical Vulnerabilities This month, Microsoft is addressing 25 vulnerabilities that are rated "critical".
The vulnerabilities rated as "critical" are listed be
Talos
Microsoft Patch Tuesday - April 2018
blogs_talos·2018-04-10·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - April 2018
## Microsoft Patch Tuesday - April 2018Today, Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 65 new vulnerabilities and one advisory, with 25 of them rated critical, 39 of them rated important and one of them rated moderate. These vulnerabilities impact Microsoft Windows, Internet Explorer, Microsoft Edge, Microsoft Office, Windows kernel, Windows Hyper-V, Microsoft Scripting Engine and more.
In addition, an update for Adobe Flash Player was released.
### Critical VulnerabilitiesThis month, Microsoft is addressing 25 vulnerabilities that are rated "critical".
The vulnerabilities rated as "critical" are listed below:
CVE-2018-0870 - Internet Explorer Me
Bugzilla
CVE-2018-1999040 jenkins-plugin-kubernetes: credentials Information Exposure
bugzilla·2018-08-02·CVSS 8.8
CVE-2018-1999040 [HIGH] CVE-2018-1999040 jenkins-plugin-kubernetes: credentials Information Exposure
CVE-2018-1999040 jenkins-plugin-kubernetes: credentials Information Exposure
An exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.10.1 and earlier in KubernetesCloud.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.
References:
https://jenkins.io/security/advisory/2018-07-30/#SECURITY-1016
Discussion:
OCP 3.11 is shipping kubernetes plugin version 1.12.1 so is not affected by this flaw.
http://www.securityfocus.com/bid/103601http://www.securitytracker.com/id/1040656https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-1016http://www.securityfocus.com/bid/103601http://www.securitytracker.com/id/1040656https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-1016
2018-04-12
Published