9.3

CVE-2018-8332

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability." This affects Windows 7, Microsoft Office, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftOffice Version2016 SwEditionclick-to-run
MicrosoftOffice For Mac Version2016
MicrosoftWindows 10 Version-
MicrosoftWindows 10 Version1607
MicrosoftWindows 10 Version1703
MicrosoftWindows 10 Version1709
MicrosoftWindows 10 Version1803
MicrosoftWindows 7 Version- Updatesp1
MicrosoftWindows 8.1 Version-
MicrosoftWindows 8.1 Version- SwEditionrt
MicrosoftWindows Server Version2008 Updater2 Editionsp1 HwPlatformitanium
MicrosoftWindows Server Version2008 Updater2 Editionsp1 HwPlatformx64
MicrosoftWindows Server Version2008 Updatesp2
MicrosoftWindows Server Version2012
MicrosoftWindows Server Version2012 Updater2
MicrosoftWindows Server Version2016
MicrosoftWindows Server Version2016 Update1709
MicrosoftWindows Server Version2016 Update1803
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 51.16% 0.978
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C