CVE-2015-1670
The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2, allows remote attackers to obtain sensitive information from process memory via a crafted OpenType font on a web site, aka "OpenType Font…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2, allows remote attackers to obtain sensitive information from process memory via a crafted OpenType font on a web site, aka "OpenType Font Parsing Vulnerability."
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 15.98% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- microsoft/.net framework
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/74485Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1032281Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-044
- http://www.securityfocus.com/bid/74485Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1032281Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-044
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.