SOURCE FACT
Microsoft · Windows
A remote code execution vulnerability exists when the Windows kernel-mode driver improperly handles TrueType fonts.
Required action
Apply updates per vendor instructions.
CISA notes
https://nvd.nist.gov/vuln/detail/CVE-2014-4148
View source evidence →