Record summary

CVE-2019-1149 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.

Description

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1144, CVE-2019-1145, CVE-2019-1150, CVE-2019-1151, CVE-2019-1152.

Description source: GitHub Advisory

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

Showing 12 of 29
ProductSourceVersion rangeStatus
CVE List16.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected

Windows 10 Version 1709 for 32-bit Systems

Browse Microsoft / Windows 10 Version 1709 for 32-bit Systems
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected

Windows 10 Version 1903 for 32-bit Systems

Browse Microsoft / Windows 10 Version 1903 for 32-bit Systems
CVE List10.0.0 to < publicationaffected

Windows 10 Version 1903 for ARM64-based Systems

Browse Microsoft / Windows 10 Version 1903 for ARM64-based Systems
CVE List10.0.0 to < publicationaffected

Windows 10 Version 1903 for x64-based Systems

Browse Microsoft / Windows 10 Version 1903 for x64-based Systems
CVE List10.0.0 to < publicationaffected
CVE List6.1.0 to < publicationaffected

Proofs of concept

1

Catalogued exploits

ExploitDBMicrosoft Font Subsetting - DLL Heap Corruption in FixSbitSubTablesExploitDB exploitby Google Security ResearchNot analyzed1 file
ExploitDB

PoC details

References

3