First published: Sat Aug 15 2015(Updated: )
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, Silverlight before 5.1.40728, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allow remote attackers to execute arbitrary code via a crafted TrueType font, aka "TrueType Font Parsing Vulnerability," a different vulnerability than CVE-2015-2463.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft .NET Framework 4 | =3.0-sp2 | |
Microsoft .NET Framework 4 | =4.0 | |
Microsoft .NET Framework 4 | =4.5 | |
Microsoft .NET Framework 4 | =4.5.1 | |
Microsoft .NET Framework 4 | =4.5.2 | |
Microsoft .NET Framework 4 | =4.6 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Vista | =sp2 | |
Microsoft .NET Framework 4 | =3.5.1 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft .NET Framework 4 | =3.5 | |
Windows 10 | ||
Microsoft Windows 8.0 | ||
Microsoft Windows | ||
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft Live Meeting | =2007 | |
Microsoft Lync 2010 | =2010 | |
Microsoft Lync 2010 | =2010 | |
Microsoft Lync 2010 | =2013-sp1 | |
Microsoft Lync | =2013-sp1 | |
Microsoft Office | =2007-sp3 | |
Microsoft Office | =2010-sp2 | |
Microsoft Silverlight | <=5.1.40416.0 | |
Microsoft Windows 7 | ||
Microsoft Windows 8.0 | ||
Microsoft Windows | ||
Microsoft Windows RT | ||
Microsoft Windows RT | ||
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft Windows Vista | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2464 is rated as important by Microsoft due to potential remote code execution risk.
Mitigation for CVE-2015-2464 involves applying the corresponding Microsoft security updates provided in MS15-080.
CVE-2015-2464 affects Microsoft Windows Vista, Windows 7, Windows 8, Windows 8.1, Windows Server 2008, and various versions of Microsoft Office and Lync.
Yes, CVE-2015-2464 can be exploited remotely without user interaction through specially crafted web content.
The best approach for CVE-2015-2464 is to apply the latest security updates, as workarounds may not fully mitigate the vulnerability.