microsoft windows-server-2008 CVE-2010-0018 vulnerability in Microsoft Products
Published on January 13, 2010

product logo product logo
Integer overflow in the Embedded OpenType (EOT) Font Engine (t2embed.dll) in Microsoft Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code via compressed data that represents a crafted EOT font, aka "Microtype Express Compressed Fonts Integer Flaw in the LZCOMP Decompressor Vulnerability."

Vendor Advisory NVD


Products Associated with CVE-2010-0018

Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.

 
 
 
 
 
 

Exploit Probability

EPSS
68.95%
Percentile
98.60%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.