CVE-2010-2740
Microsoft Windows XP/SP3 & Server 2003 - Privilege Escalation
Title source: llmDescription
The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly perform memory allocation during font parsing, which allows local users to gain privileges via a crafted application, aka "OpenType Font Parsing Vulnerability."
References (4)
Core 4
Core References
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-078
Vendor Advisory x_refsource_confirm
http://support.avaya.com/css/P8/documents/100113218
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7258
US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA10-285A.html
Scores
EPSS
0.0181
EPSS Percentile
76.4%
Details
CWE
CWE-264
Status
published
Products (3)
microsoft/windows_2003_server
microsoft/windows_server_2003
microsoft/windows_xp
(2 CPE variants)
Published
Oct 13, 2010
Tracked Since
Feb 18, 2026