CVE-2015-1671
KEVmassTrueType Font Parsing RCE in Microsoft Windows, .NET, Office, Lync, and Silverlight
CISA: Microsoft Windows Remote Code Execution Vulnerability
CVE-2015-1671 is a remote code execution vulnerability in components of Microsoft Windows, .NET Framework, Office, Lync, and Silverlight that fail to properly handle TrueType fonts. An attacker triggers it by getting a victim's system to process a specially crafted TrueType font embedded in delivered content, such as a document or web-borne material, which is a classic exploit-kit delivery vector. Successful exploitation yields arbitrary code execution on the affected machine, giving the attacker control at the privileges of the affected process and a path to full system compromise. Any Windows environment running unpatched versions of the affected components is exposed, with CISA specifically listing Microsoft Windows as the affected product. Exploitation is confirmed in the wild: the flaw is in the CISA Known Exploited Vulnerabilities catalog (added 2022-05-25) and carries a 54.6% EPSS probability of exploitation within 30 days (99th percentile), though no public PoC is cataloged and ransomware use is listed as unknown.
What to do: Apply the May 2015 Microsoft security updates (MS15-044 for Windows font drivers, .NET Framework, Office, and Silverlight, and the related Lync/Silverlight update MS15-049) across all workstations and servers, as CISA's KEV required action mandates patching per vendor instructions. Because exploit kits historically delivered this flaw via web-borne content, prioritize user-facing systems and verify that Silverlight and .NET Framework font-parsing fixes are installed, not just OS-level patches; hosts with no supported patch path should restrict rendering of untrusted documents and web content.
| Microsoft Windows | — |
| Microsoft .NET Framework | — |
| Microsoft Office | — |
| Microsoft Lync | — |
| Microsoft Silverlight | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- Windows
- Weakness
- CWE-19