CVE-2012-0159

Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview; Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Silverlight 4 before 4.1.10329; and Silverlight 5 before 5.1.10411 allow remote attackers to execute arbitrary code via a crafted TrueType font (TTF) file, aka "TrueType Font Parsing Vulnerability."

Published: 2012-05-09 Last update: 2026-04-29 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2012-0159 is rated High Risk (73.4/100): CVSS Critical severity, with high exploitation likelihood (EPSS 64.64%, 98th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +1.74% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2012-0159

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-03-05 62.90% 64.64% +1.74%
2 2025-12-28 59.49% 62.90% +3.41%
3 2025-12-27 59.49%

Full EPSS history (19 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2012-0159

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
9.3 2.0 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
8.6 10.0 [email protected]

Weakness enumeration for CVE-2012-0159

Affected software / configurations for CVE-2012-0159

Vendor Product Version Raw CPE
microsoft office 2003 cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:*
microsoft office 2007 cpe:2.3:a:microsoft:office:2007:sp2:*:*:*:*:*:*
microsoft office 2007 cpe:2.3:a:microsoft:office:2007:sp3:*:*:*:*:*:*
microsoft office 2010 cpe:2.3:a:microsoft:office:2010:*:*:*:*:*:*:*
microsoft office 2010 cpe:2.3:a:microsoft:office:2010:sp1:*:*:*:*:*:*
microsoft windows_7 cpe:2.3:o:microsoft:windows_7:*:*:*:*:*:*:*:*
microsoft windows_7 cpe:2.3:o:microsoft:windows_7:-:sp1:x64:*:*:*:*:*
microsoft windows_7 cpe:2.3:o:microsoft:windows_7:-:sp1:x86:*:*:*:*:*
microsoft windows_8 consumer_preview cpe:2.3:o:microsoft:windows_8:consumer_preview:*:*:*:*:*:*:*
microsoft windows_server_2008 cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*
microsoft windows_server_2008 r2 cpe:2.3:o:microsoft:windows_server_2008:r2:*:*:*:*:*:*:*
microsoft windows_server_2008 r2 cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*
microsoft windows_vista cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*
microsoft windows_xp cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*
microsoft windows_xp cpe:2.3:o:microsoft:windows_xp:*:sp3:*:*:*:*:*:*
microsoft silverlight 4.0.50401.0 cpe:2.3:a:microsoft:silverlight:4.0.50401.0:*:*:*:*:*:*:*
microsoft silverlight 4.0.50524.00 cpe:2.3:a:microsoft:silverlight:4.0.50524.00:*:*:*:*:*:*:*
microsoft silverlight 4.0.50826.0 cpe:2.3:a:microsoft:silverlight:4.0.50826.0:*:*:*:*:*:*:*
microsoft silverlight 4.0.50917.0 cpe:2.3:a:microsoft:silverlight:4.0.50917.0:*:*:*:*:*:*:*
microsoft silverlight 4.0.51204.0 cpe:2.3:a:microsoft:silverlight:4.0.51204.0:*:*:*:*:*:*:*
microsoft silverlight 4.0.60129.0 cpe:2.3:a:microsoft:silverlight:4.0.60129.0:*:*:*:*:*:*:*
microsoft silverlight 4.0.60310.0 cpe:2.3:a:microsoft:silverlight:4.0.60310.0:*:*:*:*:*:*:*
microsoft silverlight 4.0.60531.0 cpe:2.3:a:microsoft:silverlight:4.0.60531.0:*:*:*:*:*:*:*
microsoft silverlight 4.0.60831.0 cpe:2.3:a:microsoft:silverlight:4.0.60831.0:*:*:*:*:*:*:*
microsoft silverlight 4.1.10111.0 cpe:2.3:a:microsoft:silverlight:4.1.10111.0:*:*:*:*:*:*:*
microsoft silverlight 5.0.60401.0 cpe:2.3:a:microsoft:silverlight:5.0.60401.0:*:*:*:*:*:*:*
microsoft silverlight 5.0.60818.0 cpe:2.3:a:microsoft:silverlight:5.0.60818.0:rc:*:*:*:*:*:*
microsoft silverlight 5.0.61118.0 cpe:2.3:a:microsoft:silverlight:5.0.61118.0:*:*:*:*:*:*:*

References for CVE-2012-0159

cvelogic Threat Intelligence