First published: Wed Dec 09 2015(Updated: )
The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT Gold and 8.1; Office 2007 SP3; Office 2010 SP2; Word Viewer; .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6; Skype for Business 2016; Lync 2010; Lync 2013 SP1; Live Meeting 2007 Console; and Silverlight 5 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Graphics Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Live Meeting | =2007 | |
Microsoft Lync | =2010 | |
Microsoft Lync | =2013-sp1 | |
Microsoft Office | =2007-sp3 | |
Microsoft Office | =2010-sp2 | |
Microsoft Silverlight | =5.0 | |
Microsoft Skype for Business | =2016 | |
Microsoft Word Viewer | ||
Microsoft Windows 7 | =sp1 | |
Microsoft Windows 8.0 | ||
Microsoft Windows 8.1 | ||
Microsoft Windows RT | ||
Microsoft Windows RT | ||
Microsoft Windows Server 2008 Itanium | =sp2 | |
Microsoft Windows Server 2008 Itanium | =r2-sp1 | |
Microsoft Windows Server 2008 Itanium | =r2-sp1 | |
Microsoft Windows Server 2012 x64 | ||
Microsoft Windows Server 2012 x64 | =r2 | |
Microsoft Windows Vista | =sp2 | |
Microsoft .NET Framework | =3.0-sp2 | |
Microsoft .NET Framework | =4.0 | |
Microsoft .NET Framework | =4.5 | |
Microsoft .NET Framework | =4.5.1 | |
Microsoft .NET Framework | =4.5.2 | |
Microsoft .NET Framework | =4.6 | |
Microsoft Windows Server 2008 Itanium | =sp2 | |
Microsoft Windows Vista | =sp2 | |
Microsoft .NET Framework | =3.5.1 | |
Microsoft Windows 7 | =sp2 | |
Microsoft Windows Server 2008 Itanium | =r2-sp1 | |
Microsoft .NET Framework | =3.5 | |
Microsoft Windows 10 | ||
Microsoft Windows 8.0 | ||
Microsoft Windows 8.1 | ||
Microsoft Windows Server 2012 x64 | ||
Microsoft Windows Server 2012 x64 | =r2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6108 has been classified with a critical severity level due to potential remote code execution risks.
To fix CVE-2015-6108, update your Microsoft Windows and Office products to the latest available patches.
CVE-2015-6108 affects various Microsoft products, including Windows Vista, Windows 7, Windows 8, Office 2007, and others.
You can check the list of affected software versions for CVE-2015-6108 and confirm if your system matches any listed version.
The potential impacts of CVE-2015-6108 include remote code execution, which could allow an attacker to gain control of the affected systems.