CVE-2018-1012: Input Validation
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-1010, CVE-2018-1013, CVE-2018-1015, CVE-2018-1016.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1012?
CVE-2018-1012 is classified as critical due to its potential for remote code execution.
How do I fix CVE-2018-1012?
To fix CVE-2018-1012, install the latest security updates provided by Microsoft.
Which versions of Windows are affected by CVE-2018-1012?
CVE-2018-1012 affects various versions of Windows, including Windows 7, Windows 8.1, Windows 10, and several Windows Server editions.
What type of vulnerability is CVE-2018-1012?
CVE-2018-1012 is a remote code execution vulnerability specifically related to the handling of embedded fonts in the Windows font library.
Can I exploit CVE-2018-1012 remotely?
Yes, CVE-2018-1012 can be exploited remotely through specially crafted embedded fonts.