Description
This module exploits an integer overflow flaw in the Microsoft Windows Embedded OpenType font parsing code located in win32k.sys. Since the kernel itself parses embedded web fonts, it is possible to trigger a BSoD from a normal web page when viewed with Internet Explorer.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use auxiliary/dos/windows/browser/ms09/065_eot_integermsf undefined(065_eot_integer) > show actions ...actions...msf undefined(065_eot_integer) > set ACTION < action-name >msf undefined(065_eot_integer) > show options ...show and set options...msf undefined(065_eot_integer) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub