Bad Write in TTF font parsing (win32k.sys)

Disclosed: 2015-03-01 08:29:00 By dirtybit To ibb
Unknown
Vulnerability Details
This bug was originally reported through Project Zero at Google. Alex Rice suggested to me that I could potentially receive a bounty through Hacker One so I am also opening a report here. The vulnerability reference numbers are MS15-010 CVE-2015-0059 The original bug report is https://code.google.com/p/google-security-research/issues/detail?id=172 Microsoft released a patch on 2/10/15 https://technet.microsoft.com/library/security/dn903755.aspx Repros, loader, and minidumps are attached
Actions
View on HackerOne
Report Stats
  • Report ID: 48100
  • State: Closed
  • Substate: resolved
  • Upvotes: 1
Share this report