Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Uniscribe (aka new Unicode Script Processor) implementation in USP10.DLL in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2, and Microsoft Office XP SP3, 2003 SP3, and 2007 SP2, does not properly validate tables associated with malformed OpenType fonts, which allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) Office document, aka "Uniscribe Font Parsing Engine Memory Corruption Vulnerability."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Microsoft Windows和Microsoft Office 'USP10.DLL' Uniscribe实施输入验证漏洞
Vulnerability Description
Windows和Office产品中所使用的Unicode Scripts Processor(usp10.dll)组件没有正确的验证OpenType字体布局中的表格,用户使用支持嵌入式OpenType字体的应用程序查看了特制文档或网页就可能导致远程执行代码。成功利用此漏洞的攻击者可以获得与本地用户相同的用户权限。
CVSS Information
N/A
Vulnerability Type
N/A