CVE-2021-26876: OpenType Font Parsing Remote Code Execution Vulnerability
OpenType Font Parsing Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.1440Patch KB5000808 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.867Patch KB5000802 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17134.2087Patch KB5000809 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.1817Patch KB5000822
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26876?
CVE-2021-26876 is rated as critical due to its potential for remote code execution.
How do I fix CVE-2021-26876?
To fix CVE-2021-26876, apply the latest security updates provided by Microsoft for affected Windows versions.
What are the affected products for CVE-2021-26876?
CVE-2021-26876 affects multiple versions of Microsoft Windows 10 and Windows Server 2016.
Can CVE-2021-26876 be exploited without user interaction?
Yes, CVE-2021-26876 can potentially be exploited without user interaction through malicious OpenType fonts.
What is the impact of CVE-2021-26876 on systems?
The impact of CVE-2021-26876 includes the possibility of an attacker executing arbitrary code on an affected system.