CVE-2015-2460
published 2015-08-15CVE-2015-2460: ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1…
PriorityP271critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
31.33%
98.1th percentile
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability."
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Pool tag 'Adbe' (Adobe's font driver) is associated with the vulnerable allocation; use kernel pool tag monitoring to detect anomalous allocation/free patterns around this tag. ↗
- →Exploitation involves a suspected use-after-free on a linked list of 'Adbe' pool structures in ATMFD.DLL; the ESI register holds a stale [F/B]link pointing to unmapped or freed memory at crash time. ↗
- →Delivery vector is a crafted OpenType font file (OTF); inspect font files loaded by csrss.exe or delivered via documents/web content for malformed CFF tables. ↗
- ·Crash is easiest to reproduce with Special Pools enabled for ATMFD.DLL; on default Windows installations the crash may be delayed or less deterministic. ↗
- ·The two crash offsets (ATMFD+0x3440b and ATMFD+0x3440e) correspond to the same root cause but manifest differently depending on whether ESI accidentally points to mapped memory; both should be treated as the same vulnerability. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://www.securitytracker.com/id/1033238https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-080https://www.exploit-db.com/exploits/37921/http://www.securitytracker.com/id/1033238https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-080https://www.exploit-db.com/exploits/37921/
2015-08-15
Published