9.3
CVSSv2

CVE-2015-2462

Published: 15/08/2015 Updated: 15/05/2019
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote malicious users to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft .net_framework 4.5.2

microsoft .net_framework 4.6

microsoft .net_framework 4.0

microsoft .net_framework 4.5.1

microsoft .net_framework 3.0

microsoft .net_framework 4.5

microsoft .net_framework 3.5.1

microsoft .net_framework 3.5

microsoft windows vista -

microsoft windows 7 -

microsoft windows server 2012 -

microsoft windows rt -

microsoft windows server 2008 r2

microsoft windows 8 -

microsoft windows 8.1 -

microsoft windows 10 -

microsoft windows server 2008 -

microsoft windows server 2012 r2

microsoft windows rt 8.1 -

Exploits

Source: codegooglecom/p/google-security-research/issues/detail?id=392&can=1 We have encountered a number of Windows kernel crashes in the ATMFDDLL OpenType driver while processing corrupted OTF font files, such as: --- DRIVER_PAGE_FAULT_IN_FREED_SPECIAL_POOL (d5) Memory was referenced after it was freed This cannot be protected by ...