A remote code execution vulnerability exists when the Windows kernel-mode driver improperly handles TrueType fonts.