Link to home
Start Free TrialLog in
Avatar of JDI-IT
JDI-IT

asked on

Is downloading fonts in IE 10 safe?

My organization currently has the "font download" option disabled in the Internet zone of ie10.  I believe this was done to prevent fonts from running malicious code.  I saw that back in 2013 there was a ms security bulletin that addressed the issue.  Would it be a big security risk to enable font downloading at this point?
Avatar of gheist
gheist
Flag of Belgium image

Fonts are part of html5, much smaller danger than java plugin or flash plugin.
Given later are almost permanently vulnerable and not being patched, a font or 10 will not make significant damage.
Even cleartype was patched once, it does not mean it is no longer vulnerable (and whole IE was swapped like 20 times in meantime, still nowhere close to secure)...
I assume you know all about EMET and IE safe  modes...
Avatar of JDI-IT
JDI-IT

ASKER

Thanks for the info gheist!  Yes, we currently have EMET deployed and we've looked into deploying IE in protected mode.
ASKER CERTIFIED SOLUTION
Avatar of gheist
gheist
Flag of Belgium image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial