vulnerability
Microsoft Windows: CVE-2018-0760: Windows EOT Font Engine Information Disclosure Vulnerability
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 2 | (AV:L/AC:L/Au:N/C:P/I:N/A:N) | Feb 13, 2018 | Feb 13, 2018 | Sep 5, 2025 |
Severity
2
CVSS
(AV:L/AC:L/Au:N/C:P/I:N/A:N)
Published
Feb 13, 2018
Added
Feb 13, 2018
Modified
Sep 5, 2025
Description
The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1, Windows Server 2008 R2, and Windows Server 2012 allows information disclosure, due to how the Windows EOT font engine handles embedded fonts, aka "Windows EOT Font Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0755, CVE-2018-0761, and CVE-2018-0855.
Solutions
microsoft-windows-windows_server_2012-kb4074589msft-kb4074587-038b7343-567a-489c-9a7b-99359061b585msft-kb4074587-12655426-1147-4823-a167-6924f81938a4msft-kb4074587-4301df02-71e1-42bc-8c03-4cc5bdb33240msft-kb4074587-69e514c5-3b93-4b7f-85cc-fceefccd381fmsft-kb4074587-6c08b956-dc76-4828-8c5f-1e3d390135f9msft-kb4074587-ae42a70d-ccc6-4ef7-9590-db44662ef5c0msft-kb4074589-0988c161-fcc9-4a26-8f86-fe981b5e3a64msft-kb4074589-0f25d490-4286-470c-8d1d-6a9ad4106b42
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.