CVE-2012-0159 is a critical remote code execution vulnerability affecting multiple Microsoft products, including various versions of Windows, Office, and Silverlight. It allows attackers to execute arbitrary code by tricking a user into opening a specially crafted TrueType font (TTF) file. With a CVSS score of 9.3, this vulnerability is highly severe due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. Despite its high severity and EPSS score, there is no public exploit intelligence available (Metasploit, Nuclei, ExploitDB), nor is it listed in CISA's KEV catalog, suggesting it is not currently under active exploitation. Community discussion and media coverage for this CVE are also minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2003CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:* | ||
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2007:sp2:*:*:*:*:*:* | ||
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2007:sp3:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2010:*:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2010:sp1:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.