Microsoft Font Driver Remote Code Execution Vulnerability
RISK: Extremely High Risk
TYPE: Operating Systems - Windows OS
A vulnerability was found in the Windows Adobe Type Manager Library. A remote user can trigger arbitrary code execution on the target system.
A remote user can create a specially crafted OpenType font file that, when loaded by the target user, will trigger a flaw in the Windows Adobe Type Manager Library and execute arbitrary code on the target system.
NOTE: Exploits may be available for this vulnerability.
Impact
- Remote Code Execution
System / Technologies affected
- Microsoft Windows Vista SP2
- Microsoft Windows Server 2008
- Microsoft Windows 7
- Microsoft Windows Server 2008 R2
- Microsoft Windows 8 and Windows 8.1
- Microsoft Windows Server 2012 and Windows Server 2012 R2
- Microsoft Windows RT and Windows RT 8.1
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
https://technet.microsoft.com/en-us/library/security/MS15-078
Vulnerability Identifier
Source
Related Link
Share with