Vulnerability Details CVE-2012-0159
Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview; Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Silverlight 4 before 4.1.10329; and Silverlight 5 before 5.1.10411 allow remote attackers to execute arbitrary code via a crafted TrueType font (TTF) file, aka "TrueType Font Parsing Vulnerability."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.666
EPSS Ranking 98.4%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2012-0159
-
cpe:2.3:a:microsoft:office:2003
-
cpe:2.3:a:microsoft:office:2007
-
cpe:2.3:a:microsoft:office:2010
-
cpe:2.3:a:microsoft:silverlight:4.0.50401.0
-
cpe:2.3:a:microsoft:silverlight:4.0.50524.00
-
cpe:2.3:a:microsoft:silverlight:4.0.50826.0
-
cpe:2.3:a:microsoft:silverlight:4.0.50917.0
-
cpe:2.3:a:microsoft:silverlight:4.0.51204.0
-
cpe:2.3:a:microsoft:silverlight:4.0.60129.0
-
cpe:2.3:a:microsoft:silverlight:4.0.60310.0
-
cpe:2.3:a:microsoft:silverlight:4.0.60531.0
-
cpe:2.3:a:microsoft:silverlight:4.0.60831.0
-
cpe:2.3:a:microsoft:silverlight:4.1.10111.0
-
cpe:2.3:a:microsoft:silverlight:5.0.60401.0
-
cpe:2.3:a:microsoft:silverlight:5.0.60818.0
-
cpe:2.3:a:microsoft:silverlight:5.0.61118.0
-
cpe:2.3:o:microsoft:windows_7:-
-
cpe:2.3:o:microsoft:windows_7:sp1
-
cpe:2.3:o:microsoft:windows_8:consumer_preview
-
cpe:2.3:o:microsoft:windows_server_2008:-
-
cpe:2.3:o:microsoft:windows_server_2008:r2
-
cpe:2.3:o:microsoft:windows_vista:-
-
cpe:2.3:o:microsoft:windows_xp:-
-
cpe:2.3:o:microsoft:windows_xp:unknown