VDB
CVE-2018-0761
CVE-2018-0761
PUBLISHED
CVSS 5.5 MEDIUM
The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1 and Windows Server 2008 R2 allows information disclosure, due to how the Windows EOT font engine handles embedded fonts, aka "Windows EOT Font Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0755, CVE-2018-0760, and CVE-2018-0855.
EPSS 8.00% · 92.3th percentile
Risk Scores
CVSS 3.0
5.5
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
8.00%
92.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| microsoft | windows_7 | |
| microsoft | windows_server_2008 | * |
| Microsoft Corporation | Microsoft Windows Embedded OpenType (EOT) font engine | Windows 7 SP1 and Windows Server 2008 R2 |
Exploit Intelligence
- 102952 (circl)
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0761 (circl)
- 1040374 (circl)
Timeline
- Feb 15, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
- Mar 11, 2023 EPSS Score
- May 13, 2023 EPSS Score