CVE-2007-1213 describes a local privilege escalation vulnerability in the TrueType Fonts rasterizer of Microsoft Windows 2000 SP4. An uninitialized function pointer, triggered by crafted TrueType fonts, allows a local attacker to gain elevated privileges. With a CVSS score of 7.2, this vulnerability is considered high severity, requiring local access with low attack complexity, and leading to complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, ExploitDB contains several proofs-of-concept related to MS07-017, which addresses this and similar GDI vulnerabilities, indicating exploit code availability. Despite this, there is no community discussion or media coverage surrounding this specific CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.