CVE-2015-1671 KEV
7.8
HIGH · CVSS 3.1 · EPSS 49% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2022-06-15.
Description
The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; Lync Basic 2013 SP1; Silverlight 5 before 5.1.40416.00; and Silverlight 5 Developer Runtime before 5.1.40416.00, allows remote attackers to execute arbitrary code via a crafted TrueType font, aka "TrueType Font Parsing Vulnerability."
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 48.99% — more likely to be exploited than 99% of all CVEs |
| On CISA KEV | yes — remediate by 2022-06-15 |
| Public exploit | none known |
| Published | 2015-05-13 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Microsoft Windows Remote Code Execution Vulnerability |
|---|---|
| Added | 2022-05-25 |
| Due | 2022-06-15 |
| Vendor / product | Microsoft / Windows |
| Ransomware use | none reported |
Affected (11)
| Vendor | Product |
|---|---|
| microsoft | .net framework |
| microsoft | live meeting |
| microsoft | lync |
| microsoft | silverlight |
| microsoft | windows 7 |
| microsoft | windows 8 |
| microsoft | windows 8.1 |
| microsoft | windows server 2003 |
| microsoft | windows server 2008 |
| microsoft | windows server 2012 |
| microsoft | windows vista |
References
- http://www.securityfocus.com/bid/74490
- http://www.securitytracker.com/id/1032281
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-044
- http://www.securityfocus.com/bid/74490
- http://www.securitytracker.com/id/1032281
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-044
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-1671
→ the Explorer · watch your stack · NVD