CVE-2015-2464: Input Validation
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, Silverlight before 5.1.40728, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allow remote attackers to execute arbitrary code via a crafted TrueType font, aka "TrueType Font Parsing Vulnerability," a different vulnerability than CVE-2015-2463.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2464?
CVE-2015-2464 is rated as important by Microsoft due to potential remote code execution risk.
How do I fix CVE-2015-2464?
Mitigation for CVE-2015-2464 involves applying the corresponding Microsoft security updates provided in MS15-080.
What systems are affected by CVE-2015-2464?
CVE-2015-2464 affects Microsoft Windows Vista, Windows 7, Windows 8, Windows 8.1, Windows Server 2008, and various versions of Microsoft Office and Lync.
Can CVE-2015-2464 be exploited remotely?
Yes, CVE-2015-2464 can be exploited remotely without user interaction through specially crafted web content.
Is there a workaround for CVE-2015-2464?
The best approach for CVE-2015-2464 is to apply the latest security updates, as workarounds may not fully mitigate the vulnerability.