본문 바로가기

취약점 정보1

Special Microsoft Bulletin Patching Remote Code Execution Flaw in OpenType Font Drivers

728x90

Microsoft just released a special "out fo band" security bulletin with a patch for a remote code execution vulnerability in Windows' OpenType font drivers. The update replaces a patch released last week (MS15-077). Microsoft rates the vulnerability critical for all currently supported versions of Windows. Microsoft says in it's bulletin, that it had information that the vulnerability was public, but had no indication that it was actively exploited. MS15-077 had been exploited at the time the MS15-077 bulletin was released last week. As a workaround, users may remove the font driver, but this may cause applications that rely on it to not be able to display certain fonts.

#AffectedContra Indications - KBKnown ExploitsMicrosoft rating(**)ISC rating(*)
clientsservers
MS15-078Remote Code Execution Vulnerability in Microsoft Font Driver (Replaces MS15-077 )
Adobe Type Manager Library atmfd.dll
CVE-2015-2426
KB 3079904Exploits Detected against related vulnerability CVE-2015-2387 (see MS015-077). Vulnerability may have been public.Severity:Critcal
Exploitability: 0
Critical
or
PATCH NOW
Important
We will update issues on this page for about a week or so as they evolve.
728x90