First published: Wed Mar 11 2015(Updated: )
Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to obtain sensitive information from kernel memory, and possibly bypass the KASLR protection mechanism, via a crafted font, aka "Adobe Font Driver Information Disclosure Vulnerability," a different vulnerability than CVE-2015-0089.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 7 | =sp1 | |
Microsoft Windows 8.0 | ||
Microsoft Windows 8.1 | ||
Microsoft Windows RT | ||
Microsoft Windows RT | ||
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft Windows Vista | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0087 is rated as important, indicating a significant potential for exploitation.
To mitigate CVE-2015-0087, apply the latest security updates provided by Microsoft for affected Windows versions.
CVE-2015-0087 affects multiple Windows versions, including Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2003 SP2, and others.
CVE-2015-0087 allows remote attackers to obtain sensitive information from the kernel memory of the affected systems.
Yes, CVE-2015-0087 is exploitable without requiring authentication, making it particularly concerning for affected systems.