CVE-2018-1015 is a remote code execution vulnerability in the Windows font library, affecting numerous Windows versions including Windows 7, 8.1, 10, and various Server editions. This flaw allows an attacker to execute arbitrary code by tricking a user into opening a specially crafted embedded font. With a CVSS score of 8.8 (High), it presents a significant risk, requiring user interaction but offering high impact on confidentiality, integrity, and availability. The attack vector is network-based with low attack complexity, making it a serious threat despite requiring user interaction. Its FAUCET Risk Score of 96/100 further emphasizes its critical nature. Currently, there is no public exploit code available in Metasploit, Nuclei, or ExploitDB, and it is not listed in the CISA KEV catalog, suggesting no active widespread exploitation. However, it has garnered community discussion and media coverage, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1703CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:* | ||
1709CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.