CVE-2011-1873: Input Validation
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 on 64-bit platforms does not properly validate pointers during the parsing of OpenType (aka OTF) fonts, which allows remote attackers to execute arbitrary code via a crafted font file, aka "Win32k OTF Validation Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1873?
CVE-2011-1873 is rated as critical, as it allows for potential remote code execution through malformed OpenType fonts.
How do I fix CVE-2011-1873?
To fix CVE-2011-1873, you should apply the latest security updates provided by Microsoft for the affected Windows versions.
Which Windows versions are affected by CVE-2011-1873?
CVE-2011-1873 affects Windows XP SP2, Windows Vista SP1 and SP2, Windows 7, and various editions of Windows Server 2003 and 2008.
What type of attack does CVE-2011-1873 enable?
CVE-2011-1873 enables attackers to execute arbitrary code on the affected systems through specially crafted OpenType fonts.
Is CVE-2011-1873 still a risk for my system?
Yes, if you're using an unsupported version of Windows that is affected by CVE-2011-1873, your system remains at risk for exploitation.