Sign in. It’s quick, free and it’s up to you.
An account is an optional way to support the work we do. Find out more.
Sign in. It’s quick, free and it’s up to you.
An account is an optional way to support the work we do. Find out more.
ALL VERSIONS OF Windows have a critical flaw that could allow people to take over computers easily.
The software giant said that the vulnerability, if exploited, “could allow remote code execution if a user opens a specially crafted document or visit an untrusted webpage that contains embedded OpenType fonts”.
The issue meant that someone could take over your computer just by getting you to open a specific document, or by directing you to a certain webpage, and exploiting how Windows Type Manager Library handles OpenType fonts, which is where the vulnerability lies.
Microsoft say an attacker could use this opportunity to “install programmes; view, change or delete data; or create new accounts with full user rights”.
The security update is rated ‘Critical’ for all supported releases of Windows such as Vista, 7, 8 and 8.1. The same issue can also be found on the Insider version of Windows 10.
Microsoft said the vulnerability was already public when it released the update but that it didn’t “have any information to indicate this vulnerability had been used to attack customers”.
Security researchers from Google’s Project Zero, FireEye and TrendMicro Company were credited with finding the flaw.
If you don’t have security updates enabled automatically, you can install the patch by running Windows Update, which can be found by going into Start and searching for the term.
To embed this post, copy the code below on your site
have your say