CVE-2015-2463
published 2015-08-15CVE-2015-2463: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and…
PriorityP271critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
34.48%
98.2th percentile
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, Silverlight before 5.1.40728, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allow remote attackers to execute arbitrary code via a crafted TrueType font, aka "TrueType Font Parsing Vulnerability," a different vulnerability than CVE-2015-2464.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | live_meeting | — | — |
| microsoft | lync | — | — |
| microsoft | lync | — | — |
| microsoft | lync_basic | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | silverlight | <= 5.1.40416.0 | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2012 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Crash occurs in win32k!fsc_RemoveDups at offset +0x85 (instruction: cmp dword ptr [eax],ebx) during TrueType font processing; monitor for kernel bugcheck 0x50 (PAGE_FAULT_IN_NONPAGED_AREA) with faulting module win32k.sys originating from this function. ↗
- →The vulnerability is triggered via crafted TrueType font files with mutations in the 'glyf' table; inspect TTF files for anomalous or malformed 'glyf' table entries. ↗
- →Exploitation path runs through NtGdiGetTextExtentExW syscall into win32k TTF rendering stack; monitor for unusual kernel calls via NtGdiGetTextExtentExW associated with font loading in non-standard processes. ↗
- →Crash manifests in csrss.exe process context; anomalous kernel crashes or hangs in csrss.exe during font rendering may indicate exploitation attempts. ↗
- →Enabling Special Pools for win32k.sys causes an immediate crash on trigger; use this as a detection/triage mechanism in sandbox environments to confirm exploitation of this bug. ↗
- ·Reproduction of the PoC may require a custom program that renders all font glyphs at various point sizes; passive delivery alone may not trigger the crash on default installations. ↗
- ·On default Windows installations (without Special Pools), the crash may occur at a different location in kernel space rather than directly in win32k!fsc_RemoveDups, complicating consistent detection. ↗
- ·Root cause was not fully determined at time of disclosure; the vulnerability is distinct from CVE-2015-2464 despite sharing the same TrueType font parsing attack surface. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g64m-cw55-x3j7: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8
ghsa_unreviewed·2022-05-14·CVSS 9.3
CVE-2015-2464 [CRITICAL] CWE-20 GHSA-g64m-cw55-x3j7: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, Silverlight before 5.1.40728, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allow remote attackers to execute arbitrary code via a crafted TrueType font, aka "TrueType Font Parsing Vulnerability," a different vulnerability than CVE-2015-2463.
GHSA
GHSA-p949-2qx8-xqq6: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8
ghsa_unreviewed·2022-05-14·CVSS 9.3
CVE-2015-2463 [CRITICAL] CWE-20 GHSA-p949-2qx8-xqq6: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, Silverlight before 5.1.40728, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allow remote attackers to execute arbitrary code via a crafted TrueType font, aka "TrueType Font Parsing Vulnerability," a different vulnerability than CVE-2015-2464.
No detection rules found.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/76239http://www.securitytracker.com/id/1033238https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-080https://www.exploit-db.com/exploits/37915/http://www.securityfocus.com/bid/76239http://www.securitytracker.com/id/1033238https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-080https://www.exploit-db.com/exploits/37915/
2015-08-15
Published