CVE-2010-2740: High severity Microsoft Windows XP vulnerability
The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly perform memory allocation during font parsing, which allows local users to gain privileges via a crafted application, aka "OpenType Font Parsing Vulnerability."
Affected Software
Event History
Frequently Asked Questions
Which systems are identified as affected?
The affected systems are Microsoft Windows XP Service Pack 2 and Service Pack 3, and Microsoft Windows Server 2003 Service Pack 2. The listed software names also include Microsoft Windows 2003 Server.
What level of access does an attacker need to exploit this issue?
Exploitation is local: an attacker must be able to run a crafted application on the affected system. No authentication is required according to the supplied vector.
What is the potential impact of successful exploitation?
A successful attacker can gain privileges on the affected system. The provided severity vector indicates complete impact to confidentiality, integrity, and availability.