CVE-2018-0855 is an information disclosure vulnerability affecting the Microsoft Windows Embedded OpenType (EOT) font engine in Windows 7 SP1 and Windows Server 2008 R2. This medium-severity vulnerability, with a CVSS score of 4.3, could allow an attacker to disclose information if a user visits a specially crafted website. The attack requires user interaction (UI:R) but has low impact on confidentiality (C:L) and no impact on integrity or availability. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. While there is limited community discussion and media coverage, its EPSS score suggests a relatively low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.