← Back to CVE List
Vulnerability Intelligence Report

CVE-2015-6108

The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT Gold and 8.1; Office 2007 SP3; Office 2010 SP2; Word Viewer; .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6; Skype for Business 2016; Lync 2010; Lync 2013 SP1; Live Meeting 2007 Console; and Silverlight 5 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Graphics Memory Corruption Vulnerability."

No Active Exploit Signals
CVSS Base Score
9.3
HIGH
EPSS Probability:26.00%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
microsoft live_meeting 2007
microsoft lync 2010, 2013
microsoft office 2007, 2010
microsoft silverlight 5.0
microsoft skype_for_business 2016
microsoft word_viewer all
microsoft windows_7 all
microsoft windows_8 all
microsoft windows_8.1 all
microsoft windows_rt all
microsoft windows_rt_8.1 all
microsoft windows_server_2008 r2
microsoft windows_server_2012 r2
microsoft windows_vista all
microsoft .net_framework 3.0, 4.0, 4.5, 4.5.1, 4.5.2, 4.6, 3.5.1, 3.5
microsoft windows_10 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
25.998%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMicrosoft Corporation · Vendor · USA
Reserved2015-08-14T00:00:00
Published2015-12-09T11:00:00
Patch Date2015-12-08
Last Updated2024-08-06T07:15:12

LINK COPIED TO CLIPBOARD