CVE-2014-4148 is a critical remote code execution vulnerability affecting numerous Microsoft Windows operating systems, including Windows 7, 8, 8.1, Server 2003, 2008, and 2012. This flaw resides in the win32k.sys kernel-mode driver and can be exploited by a remote attacker through a specially crafted TrueType font. With a CVSS score of 8.8 (High), it presents a significant risk, allowing for complete compromise of confidentiality, integrity, and availability with low attack complexity and no authentication required, though user interaction is necessary. This vulnerability has been actively exploited in the wild since October 2014, as confirmed by its presence in the KEV catalog, and has garnered substantial community discussion and media coverage, despite a lack of public exploit code in common repositories.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.