Record summary

CVE-2019-1150 has a selected CVSS score of 8.8 (high); EIP currently links 2 catalogued exploits.

Description

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1144, CVE-2019-1145, CVE-2019-1149, CVE-2019-1151, CVE-2019-1152.

Description source: GitHub Advisory

Exploitation context

Available material

Catalogued exploits
2

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 30, 2024 · Source: CVE List

Affected products and versions

Showing 12 of 28
ProductSourceVersion rangeStatus
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected

Windows 10 Version 1709 for 32-bit Systems

Browse Microsoft / Windows 10 Version 1709 for 32-bit Systems
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected

Windows 10 Version 1903 for 32-bit Systems

Browse Microsoft / Windows 10 Version 1903 for 32-bit Systems
CVE List10.0.0 to < publicationaffected

Windows 10 Version 1903 for ARM64-based Systems

Browse Microsoft / Windows 10 Version 1903 for ARM64-based Systems
CVE List10.0.0 to < publicationaffected

Windows 10 Version 1903 for x64-based Systems

Browse Microsoft / Windows 10 Version 1903 for x64-based Systems
CVE List10.0.0 to < publicationaffected
CVE List6.1.0 to < publicationaffected
CVE List6.1.0 to < publicationaffected

Proofs of concept

2

Catalogued exploits

ExploitDBMicrosoft Font Subsetting - DLL Heap Corruption in ReadTableIntoStructureExploitDB exploitby Google Security ResearchNot analyzed1 file
ExploitDB

PoC details
ExploitDBMicrosoft Font Subsetting - DLL Heap-Based Out-of-Bounds read in WriteTableFromStructureExploitDB exploitby Google Security ResearchNot analyzed1 file
ExploitDB

PoC details

References

4