CVE-2015-2387: Microsoft ATM Font Driver Privilege Escalation Vulnerability
ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server allows local users to gain privileges via a crafted application.
Other sources
ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "ATMFD.DLL Memory Corruption Vulnerability."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2387?
CVE-2015-2387 has a moderate severity rating that allows local users to gain elevated privileges.
How do I fix CVE-2015-2387?
To mitigate CVE-2015-2387, apply the appropriate security updates released by Microsoft for affected Windows versions.
Which Microsoft products are affected by CVE-2015-2387?
CVE-2015-2387 affects multiple Microsoft Windows products, including Windows 7, Windows 8/8.1, Windows Vista, and Windows Server editions.
Can CVE-2015-2387 be exploited remotely?
No, CVE-2015-2387 requires local access to the affected system for exploitation.
Is there a workaround for CVE-2015-2387?
Microsoft recommends ensuring that only trusted users have access to systems and applying security best practices as a temporary workaround.