First published: Sat Aug 15 2015(Updated: )
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft .NET Framework 4 | =3.5 | |
Microsoft Windows 10 | ||
Microsoft Windows 8.0 | ||
Microsoft Windows 8.1 | ||
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft .NET Framework 4 | =3.5.1 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft .NET Framework 4 | =3.0-sp2 | |
Microsoft .NET Framework 4 | =4.0 | |
Microsoft .NET Framework 4 | =4.5 | |
Microsoft .NET Framework 4 | =4.5.1 | |
Microsoft .NET Framework 4 | =4.5.2 | |
Microsoft .NET Framework 4 | =4.6 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Vista | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2460 is rated as critical due to its potential for remote code execution.
To fix CVE-2015-2460, apply the security updates released by Microsoft for affected versions of Windows and .NET Framework.
CVE-2015-2460 affects multiple Windows versions including Vista, Server 2008, Windows 7, 8, and 8.1.
Yes, CVE-2015-2460 allows remote attackers to execute arbitrary code on the affected systems.
There are no known reliable workarounds for CVE-2015-2460, so it is essential to apply the available patches.