CVE-2011-0033: Input Validation
The OpenType Compact Font Format (CFF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate parameter values in OpenType fonts, which allows remote attackers to execute arbitrary code via a crafted font, aka "OpenType Font Encoded Character Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0033?
CVE-2011-0033 has a high severity rating as it allows remote code execution.
How do I fix CVE-2011-0033?
To fix CVE-2011-0033, ensure that all vulnerable Microsoft Windows systems are updated with the latest security patches from Microsoft.
What versions of Windows are affected by CVE-2011-0033?
CVE-2011-0033 affects Microsoft Windows XP, Windows Vista, Windows 7, Windows Server 2003, and Windows Server 2008.
What is the exploit type for CVE-2011-0033?
CVE-2011-0033 is exploited through improper validation of OpenType fonts, leading to potential code execution.
Are there any known attacks leveraging CVE-2011-0033?
Yes, CVE-2011-0033 has been associated with attacks that exploit the vulnerability in font rendering.