CVE-2015-0093Code Injection in Microsoft Windows Server 2008

CWE-94Code Injection38 documents6 sources
Severity
9.3CRITICALNVD
EPSS
23.7%
top 3.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 11
Latest updateMay 14

Description

Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font Driver Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-0088, CVE-2015-0090, CVE-2015-0091, and CVE-2015-0092.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

Patches

🔴Vulnerability Details

9
GHSA
GHSA-ppjh-6557-7v9w: Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 82022-05-14
GHSA
GHSA-27p5-g7pw-c8rc: Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 82022-05-14
GHSA
GHSA-fvhq-wrc7-3phf: Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 82022-05-14
GHSA
GHSA-pj4g-4796-v4xv: Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 82022-05-14
GHSA
GHSA-7p87-g4q8-442j: Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 82022-05-14

🕵️Threat Intelligence

3
Talos
Microsoft Patch Tuesday for March 2015: 14 Bulletins Released; FREAK Patched2015-03-10
Talos
Microsoft Patch Tuesday for March 2015: 14 Bulletins Released; FREAK Patched2015-03-10
Zscaler
Zscaler found Multiple Security Vulnerabilities | 03-10-2015

💬Community

21
Bugzilla
CVE-2014-7935 chromium-browser: use-after-free in Speech2015-01-23
Bugzilla
CVE-2014-7943 chromium-browser: out-of-bounds read in Skia2015-01-23
Bugzilla
CVE-2014-7930 chromium-browser: use-after-free in DOM2015-01-23
Bugzilla
CVE-2014-7947 chromium-browser: out-of-bounds read in PDFium2015-01-23
Bugzilla
CVE-2014-7924 chromium-browser: use-after-free in IndexedDB2015-01-23