CVE-2018-1013: Input Validation
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-1010, CVE-2018-1012, CVE-2018-1015, CVE-2018-1016.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1013?
CVE-2018-1013 is classified as critical due to its potential for remote code execution.
How do I fix CVE-2018-1013?
To fix CVE-2018-1013, apply the latest security updates provided by Microsoft for your affected Windows version.
What operating systems are affected by CVE-2018-1013?
CVE-2018-1013 affects various Windows versions including Windows 7, Windows 8.1, and several editions of Windows Server.
What is the impact of CVE-2018-1013?
The impact of CVE-2018-1013 allows attackers to execute arbitrary code on the affected system remotely.
Is there any workaround for CVE-2018-1013?
While the primary solution is applying updates, temporarily restricting user permissions on affected systems can mitigate the risk.