CVE-2015-2387
KEVmassLocal Privilege Escalation in Microsoft ATM Font Driver (ATMFD.DLL)
CISA: Microsoft ATM Font Driver Privilege Escalation Vulnerability
CVE-2015-2387 is a privilege escalation flaw in ATMFD.DLL, the Adobe Type Manager Font Driver that ships with Microsoft Windows Server. A local attacker triggers it by running a crafted application that feeds malicious data to the font driver, causing code to execute outside the user's intended privilege level. Successful exploitation lets an attacker who already has a foothold elevate from ordinary user rights to higher system privileges, enabling full compromise of the host. Affected systems are Windows Server deployments containing the ATM font driver that lack the vendor fix; because the attack requires local code execution, exposure is primarily to hosts where users or processes can run code. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03, confirming exploitation in the wild, and it carries a high EPSS of 35.1% (98th percentile); no public PoC is known and ransomware use is unconfirmed.
What to do: Apply Microsoft updates per vendor instructions on all Windows Server systems, prioritizing legacy builds that may have missed the 2015-era font-driver patches, and verify the patched ATMFD.DLL on servers where users or applications can run code. Because exploitation requires local access, pair patching with restricting arbitrary local code execution and monitoring for post-compromise privilege escalation; federal agencies must remediate per the CISA KEV requirement.
| Microsoft ATM Font Driver (ATMFD.DLL) on Windows Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server allows local users to gain privileges via a crafted application.
- Affected
- Microsoft ATM Font Driver
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- ATM Font Driver
- Weakness
- CWE-264