CVE-2015-6103
published 2015-11-11CVE-2015-6103: The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012…
PriorityP273critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
35.29%
98.2th percentile
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Windows Graphics Memory Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-6104.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2012 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Crash/exploitation occurs during processing of a TTF font file with a malformed 'OS/2' table in win32k.sys; monitor for kernel pool corruption (PAGE_FAULT_IN_NONPAGED_AREA / bugcheck 0x50) originating from win32k!memmove within the font rendering call stack. ↗
- →Enable Special Pools for win32k.sys to reliably trigger an immediate crash on exploitation attempt, aiding in detection and forensic analysis. ↗
- →The vulnerability is triggered via crafted embedded TTF fonts; inspect documents or web content loading fonts through the Adobe Type Manager Library or GDI font rendering path (NtGdiGetTextExtentExW syscall). ↗
- ·Reproduction of the crash may require a custom program that displays all font glyphs at various point sizes; passive loading alone may not trigger the vulnerability. ↗
- ·Pool corruption may cause delayed or non-deterministic system crashes on default Windows installations, making reliable detection harder without Special Pools enabled. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8vvh-pvhm-qrm3: The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8
ghsa_unreviewed·2022-05-14·CVSS 9.3
CVE-2015-6104 [CRITICAL] CWE-20 GHSA-8vvh-pvhm-qrm3: The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Windows Graphics Memory Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-6103.
GHSA
GHSA-3gmp-3578-r3cq: The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8
ghsa_unreviewed·2022-05-14·CVSS 9.3
CVE-2015-6103 [CRITICAL] CWE-20 GHSA-3gmp-3578-r3cq: The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Windows Graphics Memory Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-6104.
No detection rules found.
Talos
Microsoft Patch Tuesday - November 2015
blogs_talos·2015-11-10·CVSS 9.3
[CRITICAL] Microsoft Patch Tuesday - November 2015
## Microsoft Patch Tuesday - November 2015
Microsoft's Patch Tuesday has arrived. Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release contains 12 bulletins addressing 53 vulnerabilities. Four bulletins are rated critical and address vulnerabilities in Edge, Internet Explorer, Windows Journal, and Windows. The remaining eight bulletins are rated important and address vulnerabilities in .NET, IPsec, Kerberos, Lync/Skype for Business, NDIS, Office, SChannel, and Winsock.
## Bulletins Rated Critical Microsoft bulletins MS15-112 through MS15-115 are rated as critical in this month's release.
MS15-112 and MS15-113 are this month's Internet Explorer and Edge security bulletin respectively
Talos
Microsoft Patch Tuesday - November 2015
blogs_talos·2015-11-10·CVSS 9.3
[CRITICAL] Microsoft Patch Tuesday - November 2015
Microsoft's Patch Tuesday has arrived. Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release contains 12 bulletins addressing 53 vulnerabilities. Four bulletins are rated critical and address vulnerabilities in Edge, Internet Explorer, Windows Journal, and Windows. The remaining eight bulletins are rated important and address vulnerabilities in .NET, IPsec, Kerberos, Lync/Skype for Business, NDIS, Office, SChannel, and Winsock.
### Bulletins Rated Critical Microsoft bulletins MS15-112 through MS15-115 are rated as critical in this month's release.
MS15-112 and MS15-113 are this month's Internet Explorer and Edge security bulletin respectively. In total, 25 vulnerabilities are addresse
http://packetstormsecurity.com/files/134397/Microsoft-Windows-Kernel-Win32k.sys-TTF-Font-Processing-Buffer-Overflow.htmlhttp://www.securitytracker.com/id/1034114https://code.google.com/p/google-security-research/issues/detail?id=506https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-115https://www.exploit-db.com/exploits/38714/http://packetstormsecurity.com/files/134397/Microsoft-Windows-Kernel-Win32k.sys-TTF-Font-Processing-Buffer-Overflow.htmlhttp://www.securitytracker.com/id/1034114https://code.google.com/p/google-security-research/issues/detail?id=506https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-115https://www.exploit-db.com/exploits/38714/
2015-11-11
Published