Skip to content

WINDOWS UPDATE breaks Quark, Corel, who knows what else?

Featured Replies

This topic was imported from the Typophile platform

If you use OpenType fonts with PS outlines (.otf) or PostScript Type 1 fonts, reportedly the latest Windows update is a bit dangerous. Read this before you decide to install!

http://graphics-unleashed.unleash.com/2012/12/windows-update-kb2753842-w...

NOTE: I have not verified this in person, as I don't use Corel or Quark apps. I also don't yet know whether any other major apps may be affected.

Thanks for the link, Thomas. A number of my PC-using colleagues complained today that their Powerpoint presentations no longer properly display our OpenType corporate font.

Thanks for the warning. I use a Mac but I'm passing the message along to some clients who use PCs to view files I send them such as PowerPoints.

  • Author

Apparently PowerPoint is affected in presentation mode only. Extra dangerous as one could not know there was a problem until trying to actually present. Ouch.

Thank you Thomas.
I spend my whole day to correct the problem, uninstalled and installed several things. Just came across your this thread and knew the reason of the problem. My all documents formatting appeared to be destroyed in MS Word 2010.
After reading this I also uninstalled all the updates along with the above mentioned one and re-installed the MS Word 2010 but in vain.
I have to wait a few days and see if Microsoft releases any fix. The other way is to re-install Windows XP and every thing, quite a long work.
MZ,

Important question, I suppose: Is the use of fonts as a vector for distributing malware and viruses more than a theoretical issue?

I’m planning to release my next typeface in .ttf format only, rather than .otf—for issues concerning screen rendering—this news suggest another reason.

Bear in mind, this isn't the first Windows update to fix security bugs in its font-handling code, apparently it's just the first one to break functionality. And from what I can gather, this latest vulnerability affects TrueType fonts as well; the update only breaks OTF fonts since they typically use a different system rasterizer and API call. But the overall threat does seem more serious now that every major browser supports webfonts, so simply visiting a website could load a malicious font.

So what, if anything, is Microsoft doing about the issue. Are they wanting sales in Apple products to increase?

"I’m planning to release my next typeface in .ttf format only, rather than .otf—for issues concerning screen rendering—..."

Nick, I think that's trowing the baby out wit da bat water. I'm sure they'll fix it soon, with the main reason to support .otf on windows being issues concerning screen rendering of .ttfs.

These font security patches sure are important to keep us all safe from malicious fonts.

  • 2 weeks later...
  • Author

Yes, all fixed now. Microsoft jumped on it fairly quickly. Nine days from release of bad patch to release of fixed patch.

Create an account or sign in to comment

Important Information

We are placing functional cookies on your device to help make this website better.

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.