CVE-2009-2514
11.11.2009, 19:30
win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse font code during construction of a directory-entry table, which allows remote attackers to execute arbitrary code via a crafted Embedded OpenType (EOT) font, aka "Win32k EOT Parsing Vulnerability."
Vendor | Product | Version |
---|---|---|
microsoft | windows_2000 | * |
microsoft | windows_2003_server | * |
microsoft | windows_2003_server | * |
microsoft | windows_2003_server | * |
microsoft | windows_server_2008 | * |
microsoft | windows_server_2008 | * |
microsoft | windows_server_2008 | * |
microsoft | windows_server_2008 | * |
microsoft | windows_server_2008 | - |
microsoft | windows_server_2008 | - |
microsoft | windows_vista | * |
microsoft | windows_vista | * |
microsoft | windows_vista | * |
microsoft | windows_vista | * |
microsoft | windows_xp | * |
microsoft | windows_xp | * |
microsoft | windows_xp | - |
𝑥
= Vulnerable software versions
References