CVE-2015-1671
published 2015-05-13CVE-2015-1671: The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting…
PriorityP186high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-06-15
Exploited in the wild
EPSS
54.63%
98.9th percentile
The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; Lync Basic 2013 SP1; Silverlight 5 before 5.1.40416.00; and Silverlight 5 Developer Runtime before 5.1.40416.00, allows remote attackers to execute arbitrary code via a crafted TrueType font, aka "TrueType Font Parsing Vulnerability."
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | live_meeting | — | — |
| microsoft | lync | — | — |
| microsoft | lync | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | silverlight | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2015-1671 is exploited via a crafted TrueType font delivered through exploit kits (notably Angler EK) targeting Microsoft Silverlight, enabling drive-by download attacks via malvertising or compromised web pages. ↗
- →The vulnerability is triggered when Windows, .NET Framework, Office, Lync, or Silverlight components fail to properly handle TrueType fonts — monitor for anomalous TrueType font parsing activity in these products. ↗
- →Delivery mechanism is a crafted TrueType font file; inspect network traffic and file drops for malformed TTF files targeting Silverlight or .NET Framework processes. ↗
- ·Recorded Future's analysis was a meta-analysis of web references and did not include reverse engineering of malware; specific exploit kit infrastructure details for CVE-2015-1671 are not individually documented. ↗
- ·Silverlight 5 versions before 5.1.40416.00 are confirmed vulnerable; patching to this version or later is required per vendor instructions. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gr4p-px5x-x8jm: The Windows DirectWrite library, as used in Microsoft
ghsa_unreviewed·2022-05-14
CVE-2015-1671 [HIGH] GHSA-gr4p-px5x-x8jm: The Windows DirectWrite library, as used in Microsoft
The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; Lync Basic 2013 SP1; Silverlight 5 before 5.1.40416.00; and Silverlight 5 Developer Runtime before 5.1.40416.00, allows remote attackers to execute arbitrary code via a crafted TrueType font, aka "TrueType Font Parsing Vulnerability."
VulnCheck
Microsoft Windows Remote Code Execution Vulnerability
vulncheck·2015·CVSS 7.8
CVE-2015-1671 [HIGH] CWE-19 Microsoft Windows Remote Code Execution Vulnerability
Microsoft Windows Remote Code Execution Vulnerability
A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://cybersecurityworks.com/pdf/ransomware/Spotlight_Ransomware2021.pdf; https://dl.acm.org/doi/pdf/10.1145/3465481.3465758; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-06-15
CISA
Microsoft Windows Remote Code Execution Vulnerability
cisa·2022-05-25·CVSS 7.8
CVE-2015-1671 [HIGH] CWE-19 Microsoft Windows Remote Code Execution Vulnerability
Vulnerability: Microsoft Windows Remote Code Execution Vulnerability
Affected: Microsoft Windows
A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-1671
Remediation Due Date: 2022-06-15
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - May 2015
blogs_talos·2015-05-12·CVSS 4.3
[MEDIUM] Microsoft Patch Tuesday - May 2015
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release sees a total of 13 bulletins being released which address 48 CVEs. Three of the bulletins are listed as Critical and address vulnerabilities in Internet Explorer, GDI+ Font Parsing, and Windows Journal. The remaining ten bulletins are marked as Important and address vulnerabilities in Microsoft Office, Sharepoint, .NET, Silverlight, Service Control Manager, Windows Kernel, VBScript/JScript, Microsoft Management Console, and Secure Channel.
## Bulletins Rated CriticalMS15-043, MS15-044, and MS15-045 are rated Critical.
MS15-043 is this month’s Internet Explorer security bulletin with vulnerabilities in versions 6 through 11 being ad
Talos
Microsoft Patch Tuesday - May 2015
blogs_talos·2015-05-12·CVSS 4.3
[MEDIUM] Microsoft Patch Tuesday - May 2015
## Microsoft Patch Tuesday - May 2015
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release sees a total of 13 bulletins being released which address 48 CVEs. Three of the bulletins are listed as Critical and address vulnerabilities in Internet Explorer, GDI+ Font Parsing, and Windows Journal. The remaining ten bulletins are marked as Important and address vulnerabilities in Microsoft Office, Sharepoint, .NET, Silverlight, Service Control Manager, Windows Kernel, VBScript/JScript, Microsoft Management Console, and Secure Channel.
## Bulletins Rated Critical MS15-043, MS15-044, and MS15-045 are rated Critical.
MS15-043 is this month’s Internet Explorer security bulletin with vulnerabi
Recorded Future
New Kit, Same Player: Top 10 Vulnerabilities Used by Exploit Kits in 2016
blogs_recorded_future·CVSS 7.8
[HIGH] New Kit, Same Player: Top 10 Vulnerabilities Used by Exploit Kits in 2016
# Gone in a Flash: Top 10 Vulnerabilities Used by Exploit Kits
### Analysis Summary
- Adobe Flash Player provided eight of the top 10 vulnerabilities used by exploit kits in 2015.
- Vulnerabilities in Microsoft’s Internet Explorer and Silverlight are also major targets.
- Angler is currently the most popular exploit kit, regularly tied to malware including Cryptolocker.
- Identifying targeted vulnerabilities can better inform patch management functions within organizations.
- Some security professionals suggest uninstalling Adobe Flash Player. Enabling “Click to Play” is a stop-gap.
Recorded Future threat intelligence analysis of over 100 exploit kits (EKs) and known vulnerabilities identified Adobe Flash Player as the most frequently exploited product. While the role of Adobe Flash vul
Zscaler
Zscaler found Multiple Security Vulnerabilities | 05-12-2015
blogs_zscaler·CVSS 9.3
[CRITICAL] Zscaler found Multiple Security Vulnerabilities | 05-12-2015
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Recorded Future
New Kit, Same Player: Top 10 Vulnerabilities Used by Exploit Kits in 2016 | Recorded Future
blogs_recorded_future·CVSS 7.8
[HIGH] New Kit, Same Player: Top 10 Vulnerabilities Used by Exploit Kits in 2016 | Recorded Future
## Gone in a Flash: Top 10 Vulnerabilities Used by Exploit Kits
## Analysis Summary
Adobe Flash Player provided eight of the top 10 vulnerabilities used by exploit kits in 2015.
Vulnerabilities in Microsoft’s Internet Explorer and Silverlight are also major targets.
Angler is currently the most popular exploit kit, regularly tied to malware including Cryptolocker.
Identifying targeted vulnerabilities can better inform patch management functions within organizations.
Some security professionals suggest uninstalling Adobe Flash Player. Enabling “Click to Play” is a stop-gap.
Recorded Future threat intelligence analysis of over 100 exploit kits (EKs) and known vulnerabilities identified Adobe Flash Player as the most frequently exploited product. While the role of Adobe Flash vulnerabi
http://www.securityfocus.com/bid/74490http://www.securitytracker.com/id/1032281https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-044http://www.securityfocus.com/bid/74490http://www.securitytracker.com/id/1032281https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-044https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-1671
2015-05-13
Published
2022-05-25
Added to CISA KEV
Exploited in the wild