packetstormsecurity.com
http://packetstormsecurity.com/files/154086/Microsoft-Font-Subsetting-DLL-FixSbitSubTables-Heap-Corruption.html CVE-2019-1149
HIGH
Microsoft Graphics Remote Code Execution Vulnerability
Record summary
CVE-2019-1149 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1144, CVE-2019-1145, CVE-2019-1150, CVE-2019-1151, CVE-2019-1152.
Description source: GitHub Advisory
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
Showing 12 of 29| Product | Source | Version range | Status |
|---|---|---|---|
Microsoft Office 2019 for MacBrowse Microsoft / Microsoft Office 2019 for Mac | CVE List | 16.0.0 to < publication | affected |
Windows 10 Version 1507Browse Microsoft / Windows 10 Version 1507 | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1607Browse Microsoft / Windows 10 Version 1607 | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1703Browse Microsoft / Windows 10 Version 1703 | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1709Browse Microsoft / Windows 10 Version 1709 | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1709 for 32-bit SystemsBrowse Microsoft / Windows 10 Version 1709 for 32-bit Systems | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1803Browse Microsoft / Windows 10 Version 1803 | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1809Browse Microsoft / Windows 10 Version 1809 | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1903 for 32-bit SystemsBrowse Microsoft / Windows 10 Version 1903 for 32-bit Systems | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1903 for ARM64-based SystemsBrowse Microsoft / Windows 10 Version 1903 for ARM64-based Systems | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1903 for x64-based SystemsBrowse Microsoft / Windows 10 Version 1903 for x64-based Systems | CVE List | 10.0.0 to < publication | affected |
Windows 7Browse Microsoft / Windows 7 | CVE List | 6.1.0 to < publication | affected |
Proofs of concept
1Catalogued exploits
ExploitDBMicrosoft Font Subsetting - DLL Heap Corruption in FixSbitSubTablesExploitDB exploitby Google Security ResearchNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-1149 portal.msrc.microsoft.com
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1149