CVE-2015-2460: Input Validation
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2460?
CVE-2015-2460 is rated as critical due to its potential for remote code execution.
How do I fix CVE-2015-2460?
To fix CVE-2015-2460, apply the security updates released by Microsoft for affected versions of Windows and .NET Framework.
Which versions of Windows are affected by CVE-2015-2460?
CVE-2015-2460 affects multiple Windows versions including Vista, Server 2008, Windows 7, 8, and 8.1.
Can CVE-2015-2460 lead to remote code execution?
Yes, CVE-2015-2460 allows remote attackers to execute arbitrary code on the affected systems.
Is there a workaround for CVE-2015-2460 if I cannot apply the patch?
There are no known reliable workarounds for CVE-2015-2460, so it is essential to apply the available patches.