usp10.dll in the Unicode Scripts Processor in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "Uniscribe Font Parsing Engine Memory Corruption Vulnerability."
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.445
                        
                    
                    
                        
                            EPSS Ranking 97.4%