VulnerabilityModified
CVE-2019-1412
An information disclosure vulnerability exists in Windows Adobe Type Manager Font Driver (ATMFD.dll) when it fails to properly handle objects in memory, aka 'OpenType Font Driver Information Disclosure Vulnerability'.
MEDIUM 5.5EPSS 1.70%
Does this matter?
Lower severity and a low EPSS score (1.70%). Track it; it rarely justifies an emergency change on its own.
Description
An information disclosure vulnerability exists in Windows Adobe Type Manager Font Driver (ATMFD.dll) when it fails to properly handle objects in memory, aka 'OpenType Font Driver Information Disclosure Vulnerability'.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.70% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- microsoft/windows 7 · microsoft/windows 8.1 · microsoft/windows rt 8.1 · microsoft/windows server 2008 · microsoft/windows server 2012
- Source
- secure@microsoft.com
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1412Patch, Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-19-980/Third Party Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1412Patch, Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-19-980/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.