ZeroHour

CVE-2015-2387

KEVmass

Local Privilege Escalation in Microsoft ATM Font Driver (ATMFD.DLL)

CISA: Microsoft ATM Font Driver Privilege Escalation Vulnerability

CVSS
EPSS
35%p98
Published
KEV added
AI analysis

CVE-2015-2387 is a privilege escalation flaw in ATMFD.DLL, the Adobe Type Manager Font Driver that ships with Microsoft Windows Server. A local attacker triggers it by running a crafted application that feeds malicious data to the font driver, causing code to execute outside the user's intended privilege level. Successful exploitation lets an attacker who already has a foothold elevate from ordinary user rights to higher system privileges, enabling full compromise of the host. Affected systems are Windows Server deployments containing the ATM font driver that lack the vendor fix; because the attack requires local code execution, exposure is primarily to hosts where users or processes can run code. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03, confirming exploitation in the wild, and it carries a high EPSS of 35.1% (98th percentile); no public PoC is known and ransomware use is unconfirmed.

What to do: Apply Microsoft updates per vendor instructions on all Windows Server systems, prioritizing legacy builds that may have missed the 2015-era font-driver patches, and verify the patched ATMFD.DLL on servers where users or applications can run code. Because exploitation requires local access, pair patching with restricting arbitrary local code execution and monitoring for post-compromise privilege escalation; federal agencies must remediate per the CISA KEV requirement.

Affected
Microsoft ATM Font Driver (ATMFD.DLL) on Windows Server
Estimated exposure
masshistorically millions of Windows systems (driver shipped as a default component); current unpatched count unknown — ATMFD.DLL was a default Windows component across the affected era, so exposure tracks the very large installed base of unpatched legacy Windows Server systems rather than a countable deployed product.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server allows local users to gain privileges via a crafted application.

CISA Known Exploited Vulnerability
Affected
Microsoft ATM Font Driver
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
ATM Font Driver
Weakness
CWE-264

In the news