Vulnerability record · CVE-2014-4148 · published 15 October 2014
CVE-2014-4148: Windows win32k.sys TrueType font parsing remote code execution
Microsoft · Windows 7
A code injection flaw in the win32k.sys kernel-mode driver lets a crafted TrueType font trigger arbitrary code execution. Because font parsing sits in the kernel, successful exploitation crosses a major privilege boundary and affects all listed Windows client and server releases. The record notes it was exploited in the wild in October 2014.
Description
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted TrueType font, as exploited in the wild in October 2014, aka "TrueType Font Parsing Remote Code Execution Vulnerability."
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is a remotely reachable kernel code execution flaw with confirmed in-the-wild exploitation and KEV listing, though it requires user interaction.
What it is
A code injection flaw in the win32k.sys kernel-mode driver lets a crafted TrueType font trigger arbitrary code execution. Because font parsing sits in the kernel, successful exploitation crosses a major privilege boundary and affects all listed Windows client and server releases. The record notes it was exploited in the wild in October 2014.
Impact
An attacker gains arbitrary code execution in kernel mode, which typically means full control of the affected system. The CVSS 3.1 vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached remotely over the network with no privileges required, but user interaction is required (AV:N/AC:L/PR:N/UI:R), consistent with a victim opening or rendering a malicious font. No authentication is needed on the attacker's side.
Exploitation
It is listed in CISA KEV (added 2022-05-25) and the description states it was exploited in the wild in October 2014. EPSS is high at 0.598 (99th percentile), and a vendor patch reference is present.
What to do
- Apply the Microsoft MS14-058 update per vendor instructions; this is the primary fix.
- Prioritize any remaining Windows 7, 8, 8.1, RT, Server 2003, 2008, 2012 and Vista systems, since these are the affected platforms.
- Where patching is delayed, restrict untrusted font handling and block font files from untrusted sources at mail and web gateways.
- Retire or isolate end-of-life platforms such as Windows Server 2003 and Windows Vista that can no longer be fully patched.
Detection
- Hunt for win32k.sys or font-parsing crashes and unexpected kernel memory corruption events on affected hosts.
- Monitor for suspicious child processes spawned by font-rendering or document-viewing applications.
- Alert on delivery of TrueType font files from external or untrusted sources through email and web channels.
- Review endpoint telemetry for kernel-mode code execution anomalies on unpatched Windows builds.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2014-4148 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Microsoft Windows Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 June 2022.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-4148 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-4148), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.