7.1
CVSSv2

CVE-2009-3020

Published: 31/08/2009 Updated: 26/02/2019
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
VMScore: 715
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

win32k.sys in Microsoft Windows Server 2003 SP2 allows remote malicious users to cause a denial of service (system crash) by referencing a crafted .eot file in the src descriptor of an @font-face Cascading Style Sheets (CSS) rule in an HTML document, possibly related to the Embedded OpenType (EOT) Font Engine, a different vulnerability than CVE-2006-0010, CVE-2009-0231, and CVE-2009-0232. NOTE: some of these details are obtained from third party information.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows server 2003

Exploits

MS Windows 2003 (EOT File) BSOD Crash Exploit author: webDEViL githubcom/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/9417zip (2009-wwbsodzip) # milw0rmcom [2009-08-11] ...