Microsoft is working on a patch for the vulnerability in the Win32k TrueType font parsing engine. An attacker could exploit it to load malicious code on a computer in kernel mode. Microsoft’s workarounds are a few lines of code that run at an administrative command prompt. An out-of-cycle patch could take at least two weeks, a security expert says. The company has also published a quick fix that can be downloaded and applied to various Windows Server products. Infections have been detected worldwide, according to security vendor Symantec.”]

