← Back

CVE-2015-2460

nvd nist
Published: Aug 15, 2015Modified: May 6, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability."

Affected (8)

1 product
.net Framework
Configuration A
1 vulnerable · 5 platform
Vulnerable SoftwareAffected Versions
Version 3.5
Running on/withPlatform Versions
Microsoft
Windows 10
All versions
Microsoft
Windows 8
All versions
Microsoft
Windows 8.1
All versions
Microsoft
Windows Server 2012
All versions
Microsoft
Windows Server 2012
Version r2
Configuration B
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Version 3.5.1
Running on/withPlatform Versions
Microsoft
Windows 7
All versions
Microsoft
Windows Server 2008
Version r2 sp1
Configuration C
6 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Microsoft
Version 3.0 sp2
Version 4.0
Version 4.5.1
Version 4.5.2
Version 4.5
Version 4.6
Running on/withPlatform Versions
Microsoft
Windows Server 2008
All versions
Microsoft
Windows Vista
All versions

References (6)

Source: secure@microsoft.com
Third Party AdvisoryVDB Entry
Source: secure@microsoft.com
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry

Timeline

No history available yet.