ZeroHour

CVE-2015-1671

KEVmass

TrueType Font Parsing RCE in Microsoft Windows, .NET, Office, Lync, and Silverlight

CISA: Microsoft Windows Remote Code Execution Vulnerability

CVSS
EPSS
55%p99
Published
KEV added
AI analysis

CVE-2015-1671 is a remote code execution vulnerability in components of Microsoft Windows, .NET Framework, Office, Lync, and Silverlight that fail to properly handle TrueType fonts. An attacker triggers it by getting a victim's system to process a specially crafted TrueType font embedded in delivered content, such as a document or web-borne material, which is a classic exploit-kit delivery vector. Successful exploitation yields arbitrary code execution on the affected machine, giving the attacker control at the privileges of the affected process and a path to full system compromise. Any Windows environment running unpatched versions of the affected components is exposed, with CISA specifically listing Microsoft Windows as the affected product. Exploitation is confirmed in the wild: the flaw is in the CISA Known Exploited Vulnerabilities catalog (added 2022-05-25) and carries a 54.6% EPSS probability of exploitation within 30 days (99th percentile), though no public PoC is cataloged and ransomware use is listed as unknown.

What to do: Apply the May 2015 Microsoft security updates (MS15-044 for Windows font drivers, .NET Framework, Office, and Silverlight, and the related Lync/Silverlight update MS15-049) across all workstations and servers, as CISA's KEV required action mandates patching per vendor instructions. Because exploit kits historically delivered this flaw via web-borne content, prioritize user-facing systems and verify that Silverlight and .NET Framework font-parsing fixes are installed, not just OS-level patches; hosts with no supported patch path should restrict rendering of untrusted documents and web content.

Affected
Microsoft Windows
Microsoft .NET Framework
Microsoft Office
Microsoft Lync
Microsoft Silverlight
Estimated exposure
masshundreds of millions of Windows endpoints/users worldwide, plus every Office/.NET/Silverlight/Lync install on unpatched systems — Windows runs on well over a billion devices globally and the flaw spans Windows font drivers, .NET Framework, Office, Lync, and Silverlight, so the plausibly affected population as of the May 2015 patch cycle was in the hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Windows
Weakness
CWE-19

In the news