Microsoft OpenType Compact Font Format (CFF) driver contains a flaw related to the parsing of crafted OpenType fonts. This may allow a context-dependent attacker to use a crafted web page containing these fonts to execute arbitrary code.
Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability. Check the vendor advisory or solution in the references section.