Description
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted TrueType font, as exploited in the wild in October 2014, aka "TrueType Font Parsing Remote Code Execution Vulnerability."
In plain language
AI Act nowA Windows bug (CVE-2014-4148) lets attackers run code if a victim opens or views a malicious TrueType font file, so typical small businesses should patch urgently—especially if staff receive files from email or the internet.
CVE-2014-4148 is a kernel-mode remote code execution flaw in the win32k.sys TrueType font parsing path (CWE-94), triggered when an attacker persuades a user to open or view a crafted TrueType font; it requires no authentication and is listed in CISA KEV with a due date of 2022-06-15.
What to do now
- Check which Windows versions and service packs you run on each device (workstations and servers).
- Check whether Microsoft security update MS14-058 (for CVE-2014-4148) is installed on those systems.
- If MS14-058 is not installed, apply the latest available Windows updates that include the fixes referenced in MS14-058 per Microsoft’s guidance.
- After updating, verify the patch is present and restart as required by the update installer.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2014-4148 and every CVE in our database. Create a free account — no credit card required.
Create Free Account