CVE-2015-1671: Microsoft Windows Remote Code Execution Vulnerability
The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; Lync Basic 2013 SP1; Silverlight 5 before 5.1.40416.00; and Silverlight 5 Developer Runtime before 5.1.40416.00, allows remote attackers to execute arbitrary code via a crafted TrueType font, aka "TrueType Font Parsing Vulnerability."
Other sources
A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Microsoft Silverlightto a version that resolves this vulnerability.Fixed in 5.1.40416.00 - Upgrade
Upgrade
Microsoft Silverlight Developer Runtimeto a version that resolves this vulnerability.Fixed in 5.1.40416.00
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1671?
CVE-2015-1671 has a critical severity rating due to potential elevation of privilege vulnerabilities.
How do I fix CVE-2015-1671?
To fix CVE-2015-1671, apply the security updates provided by Microsoft for the affected software versions.
Which software is affected by CVE-2015-1671?
CVE-2015-1671 affects various versions of Microsoft .NET Framework, Microsoft Office, Lync, Silverlight, and several Windows operating systems.
What type of vulnerability is CVE-2015-1671?
CVE-2015-1671 is an elevation of privilege vulnerability that can allow an attacker to take control of affected systems.
Can CVE-2015-1671 be exploited remotely?
CVE-2015-1671 requires local access to exploit, making remote exploitation more complex but not impossible.