CVE-2015-1671

Description

The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; Lync Basic 2013 SP1; Silverlight 5 before 5.1.40416.00; and Silverlight 5 Developer Runtime before 5.1.40416.00, allows remote attackers to execute arbitrary code via a crafted TrueType font, aka TrueType Font Parsing Vulnerability.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
85.928

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Microsoft Office 2007 suites (KB2883029)Windows
Security Update for Microsoft Office 2010 (KB2881073) 32-Bit EditionWindows
Security Update for Microsoft Office 2010 (KB2881073) 64-Bit EditionWindows
Security Update for Microsoft .NET Framework 3.0 Service Pack 2 on Windows Server 2003 (KB3048073) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.0 Service Pack 2 on Windows Server 2003 (KB3048073) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4 on Windows Server 2003, Windows Vista and Windows Server 2008 (KB3048074) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4 on Windows Server 2003, Windows Vista and Windows Server 2008 (KB3048074) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 4.5, .NET Framework 4.5.1, and .NET Framework 4.5.2 on Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3048077) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4.5, .NET Framework 4.5.1, and .NET Framework 4.5.2 on Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3048077) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3048068) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2 (KB3048068) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3048070) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3048070) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB3048071) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB3048071) x64 bases systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3048072) x86 based systemsWindows
Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3048072) x64 bases systemsWindows
Security Update for Skype for Business 2015 (KB3039779) 32-Bit EditionWindows
Security Update for Skype for Business 2015 (KB3039779) 64-Bit EditionWindows
Security Update for Microsoft Silverlight (KB3056819)Windows
Security Update for Microsoft Silverlight (KB3056819) x64 bases systemsWindows
Security Update for Windows Server 2003 (KB3045171)Windows
Security Update for Windows Vista (KB3045171)Windows
Security Update for Windows Server 2008 (KB3045171)Windows
Security Update for Windows 7 (KB3045171)Windows
Security Update for Windows 8 (KB3045171)Windows
Security Update for Windows 8.1 (KB3045171)Windows
Security Update for Windows Server 2003 x64 Edition (KB3045171)Windows
Security Update for Windows Vista for x64-based Systems (KB3045171)Windows
Security Update for Windows Server 2008 x64 Edition (KB3045171)Windows
Security Update for Windows 7 for x64-based Systems (KB3045171)Windows
Security Update for Windows Server 2008 R2 x64 Edition (KB3045171)Windows
Security Update for Windows 8 for x64-based Systems (KB3045171)Windows
Security Update for Windows Server 2012 (KB3045171)Windows
Security Update for Windows 8.1 for x64-based Systems (KB3045171)Windows
Security Update for Windows Server 2012 R2 (KB3045171)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-17573Security Update for Microsoft Office 2007 suites (KB2883029)
PATCH-17574Security Update for Microsoft Office 2010 (KB2881073) 32-Bit Edition
PATCH-17575Security Update for Microsoft Office 2010 (KB2881073) 64-Bit Edition
PATCH-17576Security Update for Microsoft .NET Framework 3.0 Service Pack 2 on Windows Server 2003 (KB3048073)
PATCH-17577Security Update for Microsoft .NET Framework 3.0 Service Pack 2 on Windows Server 2003 (KB3048073)
PATCH-17578Security Update for Microsoft .NET Framework 4 on Windows Server 2003, Windows Vista and Windows Server 2008 (KB3048074)
PATCH-17579Security Update for Microsoft .NET Framework 4 on Windows Server 2003, Windows Vista and Windows Server 2008 (KB3048074)
PATCH-17580Security Update for Microsoft .NET Framework 4.5, .NET Framework 4.5.1, and .NET Framework 4.5.2 on Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3048077)
PATCH-17581Security Update for Microsoft .NET Framework 4.5, .NET Framework 4.5.1, and .NET Framework 4.5.2 on Windows Vista Service Pack 2, and Windows Server 2008 Service Pack 2 (KB3048077)
PATCH-17584Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3048070)
PATCH-17585Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 (KB3048070)
PATCH-17586Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB3048071)
PATCH-17587Security Update for Microsoft .NET Framework 3.5 on Windows 8 and Windows Server 2012 (KB3048071)
PATCH-17588Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3048072)
PATCH-17589Security Update for Microsoft .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2 (KB3048072)
PATCH-17590Security Update for Skype for Business 2015 (KB3039779) 32-Bit Edition
PATCH-17591Security Update for Skype for Business 2015 (KB3039779) 64-Bit Edition
PATCH-17781Security Update for Windows Server 2003 (KB3045171)
PATCH-17782Security Update for Windows Vista (KB3045171)
PATCH-17783Security Update for Windows Server 2008 (KB3045171)
PATCH-17784Security Update for Windows 7 (KB3045171)
PATCH-17785Security Update for Windows 8 (KB3045171)
PATCH-17786Security Update for Windows 8.1 (KB3045171)
PATCH-17787Security Update for Windows Server 2003 x64 Edition (KB3045171)
PATCH-17788Security Update for Windows Vista for x64-based Systems (KB3045171)
PATCH-17789Security Update for Windows Server 2008 x64 Edition (KB3045171)
PATCH-17790Security Update for Windows 7 for x64-based Systems (KB3045171)
PATCH-17791Security Update for Windows Server 2008 R2 x64 Edition (KB3045171)
PATCH-17792Security Update for Windows 8 for x64-based Systems (KB3045171)
PATCH-17793Security Update for Windows Server 2012 (KB3045171)
PATCH-17794Security Update for Windows 8.1 for x64-based Systems (KB3045171)
PATCH-17795Security Update for Windows Server 2012 R2 (KB3045171)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234