First published: Sat Aug 15 2015(Updated: )
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft .NET Framework 4 | =3.0-sp2 | |
Microsoft .NET Framework 4 | =4.0 | |
Microsoft .NET Framework 4 | =4.5 | |
Microsoft .NET Framework 4 | =4.5.1 | |
Microsoft .NET Framework 4 | =4.5.2 | |
Microsoft .NET Framework 4 | =4.6 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Vista | =sp2 | |
Microsoft .NET Framework 4 | =3.5.1 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft .NET Framework 4 | =3.5 | |
Microsoft Windows 10 | ||
Microsoft Windows 8.0 | ||
Microsoft Windows 8.1 | ||
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft Windows 10 | ||
Microsoft Windows 7 | ||
Microsoft Windows 8.0 | ||
Microsoft Windows 8.1 | ||
Microsoft Windows RT | ||
Microsoft Windows RT | ||
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft Windows Vista | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2462 is rated as a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2015-2462, apply the latest security updates provided by Microsoft for the affected Windows and .NET Framework versions.
CVE-2015-2462 affects Windows Vista SP2, Windows 7 SP1, Windows 8, Windows 8.1, Windows 10, various versions of the .NET Framework, and Windows Server 2008 and 2012.
CVE-2015-2462 is classified as a remote code execution vulnerability.
Yes, CVE-2015-2462 can be exploited remotely, allowing attackers to execute arbitrary code on the vulnerable system.